Rule library
// Detection
Impossible travel
The same account authenticating from two countries closer together in time than travel between them would allow. Strong evidence that a credential is being used by someone other than its owner.
CriticalInvestigating1alerts raisedImpossible travel
Armed
What this rule does
Rendered from the stored logic, so it cannot drift from what executes.
Same username authenticating from two countries within 180 minutes
{
"kind": "impossible_travel",
"groupBy": "username",
"withinMinutes": 180
}Revise
Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.
Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city
Alerts raised (1)
What this rule has actually caught.
| Alert | Finding | Status | Risk | Raised |
|---|---|---|---|---|
| ALT-971696 | Successful logon from Lahore, PK 41 minutes after the same account authenticated from Chicago, USA. | Investigating | 92 |
Rule
- Category
- Credential Access
- ATT&CK tactic
- Initial Access
- Technique
- T1078.004
- Kind
- Impossible travel
- State
- Armed
- Created
- 7d ago
- Last changed
- 7d ago
Firing history
- Total alerts
- 1
- First fired
- 7d ago
- Last fired
- 7d ago
- Escalated to cases
- 1
- Dismissed benign
- 0