XbowMediumFindings

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Creates an incident for each Medium severity finding reported by XBOW that is currently in an open state. These findings represent moderate security risks that should be addressed in a timely manner. Each alert is deduplicated per finding so re-ingestion of the same finding does not produce duplicate incidents.

Attribute Value
Type Analytic Rule
Solution XBOW
ID b3c5e2f9-6a8d-4127-9b2e-4f6a8c9d0e12
Severity Medium
Status Available
Kind Scheduled
Tactics Discovery, Reconnaissance, CredentialAccess
Required Connectors XbowSecurityConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
XbowAssets_CL ? ?
XbowFindings_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to XBOW