Link Search Menu Expand Document

Domain_Bandwidth_Exceeds_Threshold

ID: 100239

Description:

A domain has used more than 1GB in the last 12 hours

Repository: Group: Network Type: metaflow

Default Status:

Disabled

Tags:
Network
 

Selector:

Query:

sip:192.168.50.* OR dip:192.168.50.*

Filters:

Field MUST hit
   
Field MUST NOT hit
   

Behavior Rule:

Key Type Behavior Category
http.host asset application activity

Risks:

Risks Base Score Dimension
     

Attributes:

Alias Key
TotalBytes totalB
Device meta.device
SourceIP sip
TransBytes txB
RecvBytes rxB
Hostname s_asset.hostname
Domain http.host

Correlation Rules:

Aggregation:

Name Window Field AggType Match
ThresholdExceeded 12 hours totalB sum gt 1e+09
  Risks: BANDWIDTH_ANOMALY    

History:

User Date
em*n@fluencysecurity.com 2021 Apr 20 02:28:08 EDT

This page was automatically created/formatted on Tue, 2021 Oct 19 00:29:17 EDT, from rule_dump.json (db47c470500ce8686ead334f5eda0596)