Skip to content

Latest commit

 

History

History
23 lines (17 loc) · 763 Bytes

3.10.md

File metadata and controls

23 lines (17 loc) · 763 Bytes

3.10 - Unusual admin activity by user & country in the last 7 days

Any new admin activity by a particular user from a given country first seen in the last 7 days. Default lookback window over all admin activity in the last 60 days.

Category: Cloud Provisioning Activity
Use Cases: Detect
Data Sources: Audit Logs - Admin Activity

Queries or Rules

BigQuery Chronicle
SQL Contribute rule

Event Generation

No event generation steps provided. Contribute emulation test to this use case.

Sample Event

No log samples provided. Contribute log samples to this use case.