Navigation :
Period with Unusual Windows Security Event Sequences
Description
Triggered when Windows events occur outside of the normal baseline for a user.
Content Mapping
This content is not mapped to any local saved search. Add mapping
Use Case
Advanced Threat Detection, Insider Threat, Security Monitoring, Compliance
Category
Account Compromise, IAM Analytics, Insider Threat, Lateral Movement,
Zero TrustAlert Volume
MediumJourney
Stage 6MITRE ATT&CK Tactics
Persistence
Privilege Escalation
Initial Access
MITRE ATT&CK Techniques
Valid Accounts
MITRE Threat Groups
APT18
APT28
APT33
APT39
APT41
Carbanak
Chimera
Dragonfly 2.0
FIN10
FIN4
FIN5
FIN6
FIN8
Leviathan
Night Dragon
OilRig
PittyTiger
Sandworm Team
Silence
Soft Cell
Suckfly
TEMP.Veles
Threat Group-3390
UNC2452
Wizard Spider
menuPass
Data Sources
Windows Security