Link Search Menu Expand Document

Falcon_User_Activity

ID: 100437

Description:

CrowdStrike Falcon logged user activity by a user that was logged into its web interface. - KLK - This behavior alerts when a detail about the activity (such as user or location) is identified as New within the specified window.

Repository: Fluency Group: CrowdStrike Type: event

Default Status:

Enabled

Tags:  
CrowdStrike Falcon
   

Selector:

Query:

Filters:

Field MUST hit
@event_type @falcon
@falcon.eventType UserActivityAuditEvent
Field MUST NOT hit
   

Behavior Rule:

Key Type Behavior Category
@falcon.event.UserId username security alert

Risks:

Risks Base Score Dimension
Timeline 0 -

Attributes:

Alias Key
EventType @falcon.eventType
OperationName @falcon.event.OperationName
ServiceName @falcon.event.ServiceName
UserID @falcon.event.UserId
UserIP @falcon.event.UserIp
UTCTimestamp @falcon.event.UTCTimestamp
AuditKey @falcon.event.AuditKeyValues.Key
AuditKeyValue @falcon.event.AuditKeyValues.ValueString
Country @falcon.event._ip.country
ISP @falcon.event._ip.isp

Correlation Rules:

First Occurrence:

Name Window Fields
NewUser 1 day @falcon.event.UserId
  Risks: ML_NEW_USER
NewActivity 1 day @falcon.event.OperationName
  Risks: ML_NEW_ALERT
NewISP 10 days @falcon.event._ip.isp
  Risks: SUSPICIOUS_GEO
NewCountry 10 days @falcon.event._ip.country
  Risks: ML_NEW_GEO_COUNTRY

History:

User Date
ho*d@fluencysecurity.com 2021 Aug 31 08:20:35 EDT
ho*d@fluencysecurity.com 2021 Aug 31 16:14:48 EDT
ho*d@fluencysecurity.com 2021 Aug 31 16:16:11 EDT

This page was automatically created/formatted on Tue, 2021 Oct 19 00:29:17 EDT, from rule_dump.json (db47c470500ce8686ead334f5eda0596)