Link Search Menu Expand Document

Falcon_User_Activity_Containment_Requested

ID: 100150

Description:

CrowdStrike Falcon User Activity Containment Requested - KLK - A user has requested that Falcon perform a containment operation on an endpoint.

Repository: Fluency Group: CrowdStrike Type: event

Default Status:

Enabled

Tags:  
CrowdStrike Falcon
   

Selector:

Query:

Filters:

Field MUST hit
@event_type @falcon
@falcon.eventType UserActivityAuditEvent
@falcon.event.OperationName containment_requested
Field MUST NOT hit
   

Behavior Rule:

Key Type Behavior Category
@falcon.event.UserId username security alert

Risks:

Risks Base Score Dimension
Timeline 0 -

Attributes:

Alias Key
EventType @falcon.eventType
OperationName @falcon.event.OperationName
ServiceName @falcon.event.ServiceName
UserID @falcon.event.UserId
UserIP @falcon.event.UserIp
UTCTimestamp @falcon.event.UTCTimestamp
AuditKey @falcon.event.AuditKeyValues.Key
AuditKeyValue @falcon.event.AuditKeyValues.ValueString
ISP @falcon.event._ip.isp
Country @falcon.event._ip.country

Correlation Rules:

First Occurrence:

Name Window Fields
NewUser 10 days @falcon.event.UserId
  Risks: ML_NEW_USER
NewActivity 10 days @falcon.event.OperationName
  Risks: ML_NEW_ALERT
NewISP 10 days @falcon.event._ip.isp
  Risks: SUSPICIOUS_GEO
NewCountry 10 days @falcon.event._ip.country
  Risks: ML_NEW_GEO_COUNTRY

History:

User Date
ke*y@fluencysecurity.com 2020 Dec 15 09:28:16 EST
ke*y@fluencysecurity.com 2020 Dec 22 09:39:59 EST
ho*d@fluencysecurity.com 2021 Apr 22 08:53:24 EDT
ke*y@fluencysecurity.com 2021 Aug 25 08:13:14 EDT
ho*d@fluencysecurity.com 2021 Aug 31 00:58:42 EDT
ho*d@fluencysecurity.com 2021 Aug 31 16:18:56 EDT

This page was automatically created/formatted on Wed, 2021 Oct 13 18:38:25 EDT, from rule_dump.json (db47c470500ce8686ead334f5eda0596)