Link Search Menu Expand Document

Falcon_User_Activity_Lift_Containment_Requested

ID: 100153

Description:

CrowdStrike Falcon User Activity Lift Containment Requested - KLK - A user has requested that Falcon lift/remove a containment operation on an endpoint.

Repository: Fluency Group: CrowdStrike Type: event

Default Status:

Enabled

Tags:  
CrowdStrike Falcon
   

Selector:

Query:

Filters:

Field MUST hit
@event_type @falcon
@falcon.eventType UserActivityAuditEvent
@falcon.event.OperationName lift_containment_requested
Field MUST NOT hit
   

Behavior Rule:

Key Type Behavior Category
@falcon.event.UserId username security alert

Risks:

Risks Base Score Dimension
Timeline 0 -

Attributes:

Alias Key
EventType @falcon.eventType
OperationName @falcon.event.OperationName
ServiceName @falcon.event.ServiceName
UserID @falcon.event.UserId
UserIP @falcon.event.UserIp
UTCTimestamp @falcon.event.UTCTimestamp
AuditKey @falcon.event.AuditKeyValues.Key
AuditKeyValue @falcon.event.AuditKeyValues.ValueString
ISP @falcon.event._ip.isp
Country @falcon.event._ip.country

Correlation Rules:

First Occurrence:

Name Window Fields
NewUser 10 days @falcon.event.UserId
  Risks: ML_NEW_USER
NewActivity 10 days @falcon.event.OperationName
  Risks: ML_NEW_ALERT

History:

User Date
ke*y@fluencysecurity.com 2020 Dec 15 09:36:23 EST
ke*y@fluencysecurity.com 2020 Dec 22 09:40:25 EST
ho*d@fluencysecurity.com 2021 Apr 22 08:53:37 EDT
ke*y@fluencysecurity.com 2021 Aug 25 08:13:40 EDT
ho*d@fluencysecurity.com 2021 Aug 31 00:59:00 EDT
ho*d@fluencysecurity.com 2021 Aug 31 16:20:05 EDT

This page was automatically created/formatted on Wed, 2021 Oct 13 18:38:25 EDT, from rule_dump.json (db47c470500ce8686ead334f5eda0596)