Detect any connection to a known malicious IP (hardcoded).
Category: Network Activity
Use Cases: Detect, Respond
Data Sources: VPC Flow Logs
BigQuery | Chronicle |
---|---|
SQL | Contribute rule |
No event generation steps provided. Contribute emulation test to this use case.
No log samples provided. Contribute log samples to this use case.