Link Search Menu Expand Document

Falcon_Auth_Activity

ID: 100432

Description:

CrowdStrike Falcon AuthActivityAuditEvent

Repository: Fluency Group: CrowdStrike Type: event

Default Status:

Enabled

Tags:  
CrowdStrike Falcon
   

Selector:

Query:

Filters:

Field MUST hit
@event_type @falcon
@falcon.eventType AuthActivityAuditEvent
Field MUST NOT hit
@falcon.event.OperationName streamStarted
  streamStopped

Behavior Rule:

Key Type Behavior Category
@falcon.event.UserId username security alert

Risks:

Risks Base Score Dimension
Timeline 0 -

Attributes:

Alias Key
EventType @falcon.eventType
OperationName @falcon.event.OperationName
Success @falcon.event.Success
ServiceName @falcon.event.ServiceName
UserID @falcon.event.UserId
UserIP @falcon.event.UserIp
UTCTimestamp @falcon.event.UTCTimestamp
Country @falcon.event._ip.country
ISP @falcon.event._ip.isp

Correlation Rules:

First Occurrence:

Name Window Fields
NewUser 10 days @falcon.event.UserId
  Risks: ML_NEW_USER
NewISP 10 days @falcon.event._ip.isp
  Risks: SUSPICIOUS_GEO
NewCountry 10 days @falcon.event._ip.country
  Risks: ML_NEW_GEO_COUNTRY

History:

User Date
ho*d@fluencysecurity.com 2021 Aug 30 17:13:21 EDT
ho*d@fluencysecurity.com 2021 Aug 30 23:35:08 EDT
ho*d@fluencysecurity.com 2021 Aug 30 23:37:33 EDT
ho*d@fluencysecurity.com 2021 Aug 31 01:02:15 EDT

This page was automatically created/formatted on Wed, 2021 Oct 13 18:38:25 EDT, from rule_dump.json (db47c470500ce8686ead334f5eda0596)