Blacklisted IP Address

Blacklisted IP Address

Description

Trigerred off of core network traffic, this anomaly compares IP addresses that are visted agains the internal UBA IP Address blacklist. If IPs match, the anomaly is created.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Advanced Threat Detection

Category

Endpoint Compromise, Threat Intelligence

Alert Volume

High

Data Availability

Bad

Journey

Stage 4

MITRE ATT&CK Tactics

Command and Control
Exfiltration

MITRE ATT&CK Techniques

Custom Command and Control Protocol
Non-Application Layer Protocol
Application Layer Protocol
Exfiltration Over Alternative Protocol
Exfiltration Over C2 Channel

MITRE Threat Groups

Lazarus Group
APT3
Kimsuky
APT29
MuddyWater
Rocke
APT32
Gamaredon Group
FIN6
Stealth Falcon
Soft Cell
Frankenstein
PLATINUM
Sandworm Team
Dragonfly 2.0
Wizard Spider
Magic Hound
Ke3chang

Data Sources

Network Communication