LoFP LoFP / identity

identity rule

TitleTags
false positives may be generated by normal provisioning workflows for user device registration.
false positives may be generated by normal provisioning workflows that generate a password reset followed by a device registration.
false positives may be generated by users working out the geographic region where the organizations services or technology is hosted.
legitimate usage of some vpns may cause false positives. tune as needed.
limited to no expected false positives once a baseline of common vpn software has been completed.
this is a hunting query meant to identify rare audio devices.
this is a hunting query meant to identify rare microphone devices.
this is a hunting query meant to identify rare video devices.
while latency could simply indicate a slow network connection, when combined with other indicators, it can help build a more complete picture. tune the threshold as needed for your environment baseline.