Rule library
// Detection
Repeated authorization failures in the console
One operator hitting the permission boundary repeatedly. Usually confusion about a role, occasionally an account probing for what it can reach.
MediumInvestigating0alerts raisedThreshold
Armed
What this rule does
Rendered from the stored logic, so it cannot drift from what executes.
4+ events where eventType is PLATFORM_ACCESS_DENIED, grouped by username, within 10 minutes
{
"kind": "threshold",
"count": 4,
"where": [
{
"op": "eq",
"field": "eventType",
"value": "PLATFORM_ACCESS_DENIED"
}
],
"groupBy": "username",
"windowMinutes": 10
}Revise
Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.
Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city
Alerts raised (0)
What this rule has actually caught.
Never fired
Armed, but nothing in the retained window has matched it.
Rule
- Category
- Platform
- ATT&CK tactic
- Discovery
- Technique
- T1087
- Kind
- Threshold
- State
- Armed
- Created
- 7d ago
- Last changed
- 7d ago
Firing history
- Total alerts
- 0
- First fired
- Never
- Last fired
- Never
- Escalated to cases
- 0
- Dismissed benign
- 0