Rule library
// Detection

Impossible travel

The same account authenticating from two countries closer together in time than travel between them would allow. Strong evidence that a credential is being used by someone other than its owner.

CriticalInvestigating1alerts raisedImpossible travel
Armed

What this rule does

Rendered from the stored logic, so it cannot drift from what executes.

Same username authenticating from two countries within 180 minutes

{
  "kind": "impossible_travel",
  "groupBy": "username",
  "withinMinutes": 180
}

Revise

Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.

Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city

Alerts raised (1)

What this rule has actually caught.

Rule

Category
Credential Access
ATT&CK tactic
Initial Access
Technique
T1078.004
Kind
Impossible travel
State
Armed
Created
7d ago
Last changed
7d ago

Firing history

Total alerts
1
First fired
7d ago
Last fired
7d ago
Escalated to cases
1
Dismissed benign
0

Related