XbowMediumFindings

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Creates an incident for each Medium severity finding reported by XBOW that is currently in an open state. These findings represent moderate security risks that should be addressed in a timely manner. Each alert is deduplicated per finding so re-ingestion of the same finding does not produce duplicate incidents.

Attribute Value
Type Analytic Rule
Solution XBOW
ID b3c5e2f9-6a8d-4127-9b2e-4f6a8c9d0e12
Severity Medium
Status Available
Kind Scheduled
Tactics Discovery, Reconnaissance, CredentialAccess
Required Connectors XbowSecurityConnector
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
XbowAssets_CL
XbowFindings_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to XBOW