StealthTalkAnomalousAuth_CL

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Attribute Value
Ingestion API Supported ✓ Yes

Contents

Schema (21 columns)

Source: KQL validation test schema

Column Name Type
AppVersion string
AssignedCity string
AssignedCountry string
DeviationMinutes int
DeviceId string
EventType string
IpAddress string
IsWeekend bool
LoginBlockingSeconds int
LoginCity string
LoginCountry string
LoginTime datetime
NewDeviceId string
NewDeviceOS string
PassedAttempts int
RawEventId string
Severity string
TimeGenerated datetime
UserId string
WorkingHoursEnd string
WorkingHoursStart string

Solutions (1)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
StealthTalk Anomalous Authentication

Content Items Using This Table (8)

Analytic Rules (4)

In solution StealthTalk:

Analytic Rule Selection Criteria
StealthTalk - After hours work
StealthTalk - Login outside work zone
StealthTalk - Multi new devices registration
StealthTalk - Password brute force

Hunting Queries (3)

In solution StealthTalk:

Hunting Query Selection Criteria
StealthTalk - Account takeover sequence
StealthTalk - Brute force followed by suspicious access
StealthTalk - Impossible travel

Workbooks (1)

In solution StealthTalk:

Workbook Selection Criteria
StealthTalkAnomalousAuthMonitor

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index