Rule library
// Detection

Perimeter denial burst

A single source address repeatedly blocked at the edge in a short window, consistent with scanning or a misconfigured integration.

MediumInvestigating0alerts raisedThreshold
Armed

What this rule does

Rendered from the stored logic, so it cannot drift from what executes.

15+ events where eventType is NETWORK_DENY, grouped by sourceIp, within 10 minutes

{
  "kind": "threshold",
  "count": 15,
  "where": [
    {
      "op": "eq",
      "field": "eventType",
      "value": "NETWORK_DENY"
    }
  ],
  "groupBy": "sourceIp",
  "windowMinutes": 10
}

Revise

Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.

Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city

Alerts raised (0)

What this rule has actually caught.

Never fired

Armed, but nothing in the retained window has matched it.

Rule

Category
Discovery
ATT&CK tactic
Discovery
Technique
T1046
Kind
Threshold
State
Armed
Created
7d ago
Last changed
7d ago

Firing history

Total alerts
0
First fired
Never
Last fired
Never
Escalated to cases
0
Dismissed benign
0

Related