Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Possible Insider Threat Activity Low Identity Threat Module 1 variation

    A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    3 Hours
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Financial Theft (T1657)
    Required data: AzureAD Audit Log Microsoft Graph Logs Office 365 Audit Okta Palo Alto Networks Global Protect Third-Party VPNs XDR Agent XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: An insider threat might use their access to organizational resources for personal gain.
    Investigative actions: Check how long the user has been part of the organization. Check if the user is about to leave the company. Verify that the user is not part of a department that performs such activity as part of daily operations.

    Variations

    Indicate Insider Threat Activity

    Medium overridden

    A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. overridden