Vectra Create Incident Based on Priority for Hosts

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Create an incident when an identity is suspected to be compromised. Vectra is using AI to prioritize an entity based on multiple factors (attack rating, velocity, breadth, importance.etc.). This layer of aggregation at the entity level provides a greater signal-to-noise ratio and help analyst focus on what matters.

Attribute Value
Type Analytic Rule
Solution Vectra XDR
ID 9b51b0fb-0419-4450-9ea0-0a48751c4902
Severity Medium
Status Available
Kind Scheduled
Tactics Persistence
Techniques T1546
Required Connectors VectraXDR
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Entities_Data_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Vectra XDR