Techniques
Sample rules
Rare GCP Audit Failure Event Code
- source: elastic
- technicques:
- T1526
- T1580
Description
A machine learning job detected an unusual failure in a GCP Audit message. These can be byproducts of attempted or successful persistence, privilege escalation, defense evasion, discovery, lateral movement, or collection.
Detection logic
Rare Azure Activity Logs Event Failures
- source: elastic
- technicques:
- T1526
- T1580
Description
A machine learning job detected an unusual failure in an Azure Activity Logs message. These can be byproducts of attempted or successful persistence, privilege escalation, defense evasion, discovery, lateral movement, or collection.
Detection logic