Rule library
// Detection
Perimeter denial burst
A single source address repeatedly blocked at the edge in a short window, consistent with scanning or a misconfigured integration.
MediumInvestigating0alerts raisedThreshold
Armed
What this rule does
Rendered from the stored logic, so it cannot drift from what executes.
15+ events where eventType is NETWORK_DENY, grouped by sourceIp, within 10 minutes
{
"kind": "threshold",
"count": 15,
"where": [
{
"op": "eq",
"field": "eventType",
"value": "NETWORK_DENY"
}
],
"groupBy": "sourceIp",
"windowMinutes": 10
}Revise
Backtest before saving. Alerts already raised keep their original descriptions: they record what the rule found at the time.
Fields: eventType, username, sourceIp, destinationIp, hostname, processName, commandLine, parentProcess, action, status, country, city
Alerts raised (0)
What this rule has actually caught.
Never fired
Armed, but nothing in the retained window has matched it.
Rule
- Category
- Discovery
- ATT&CK tactic
- Discovery
- Technique
- T1046
- Kind
- Threshold
- State
- Armed
- Created
- 7d ago
- Last changed
- 7d ago
Firing history
- Total alerts
- 0
- First fired
- Never
- Last fired
- Never
- Escalated to cases
- 0
- Dismissed benign
- 0