Link Search Menu Expand Document

Falcon_User_Activity

ID: 100437

Description:

CrowdStrike Falcon logged user activity by a user that was logged into its web interface. - KLK - This behavior alerts when a detail about the activity (such as user or location) is identified as New within the specified window.

Repository: Fluency Group: CrowdStrike Type: event

Default Status:

Enabled

Tags:  
CrowdStrike Falcon
   

Selector:

Query:

Filters:

Field MUST hit
@event_type @falcon
@falcon.eventType UserActivityAuditEvent
Field MUST NOT hit
   

Behavior Rule:

Key Type Behavior Category
@falcon.event.UserId username security alert

Risks:

Risks Base Score Dimension
Timeline 0 -

Attributes:

Alias Key
EventType @falcon.eventType
OperationName @falcon.event.OperationName
ServiceName @falcon.event.ServiceName
UserID @falcon.event.UserId
UserIP @falcon.event.UserIp
UTCTimestamp @falcon.event.UTCTimestamp
AuditKey @falcon.event.AuditKeyValues.Key
AuditKeyValue @falcon.event.AuditKeyValues.ValueString
Country @falcon.event._ip.country
ISP @falcon.event._ip.isp

Correlation Rules:

First Occurrence:

Name Window Fields
NewUser 10 days @falcon.event.UserId
  Risks: ML_NEW_USER
NewActivity 10 days @falcon.event.OperationName
  Risks: ML_NEW_ALERT
NewISP 10 days @falcon.event._ip.isp
  Risks: ML_NEW_GEO_ISP
NewCountry 10 days @falcon.event._ip.country
  Risks: ML_NEW_GEO_COUNTRY

History:

User Date
ho*d@fluencysecurity.com 2021 Aug 31 08:20:35 EDT
ho*d@fluencysecurity.com 2021 Aug 31 16:14:48 EDT
ho*d@fluencysecurity.com 2021 Aug 31 16:16:11 EDT
ke*y@fluencysecurity.com 2022 Feb 23 13:48:45 EST

This page was automatically created/formatted on Wed, 2022 May 4 21:43:53 EDT, from rule_dump.json (4d88bffdfb1cea26b3985f2193033606)