Tag
medium
advisory
Detection of High-Frequency File Operations in Administrative Network Shares
1 rule 1 TTPAn anomaly-based detection analytic identifying potential insider threats or data exfiltration by monitoring for high-frequency write operations to administrative network shares via Windows Event ID 5145.
Windows
insider-threat
data-exfiltration
monitoring
1r
1t
high
threat
Cisco Duo Bulk Policy Deletion Detected
2 rules 1 TTPDetection of a Cisco Duo administrator performing a bulk deletion of more than three policies, potentially indicating malicious activity such as weakening security controls.
Duo
Insider Threat
+1
cisco-duo
policy-deletion
insider-threat
2r
1t