-
Notifications
You must be signed in to change notification settings - Fork 63
Open
Labels
new moduleNew automation moduleNew automation module
Description
I wonder if there would be an interest for such a module. It's essentially a similar concept of what we have for analysts in the entity page available for automation and a bit of what we have in UEBA.
Takes a user and return stats such as:
- Last successful logon data (timestamp + other metadata)
- Last failed logon data
- Usual user-agent-string data
- Usual contries/IPs
If there is a cloud-logon-session present in the entities (case of an AAD Protection alert), return all the info about this particular login.
That last one maybe could be added to the AAD Risk Module instead.
Metadata
Metadata
Assignees
Labels
new moduleNew automation moduleNew automation module