Techniques
Sample rules
Spike in GCP Audit Failed Messages
- source: elastic
- technicques:
- T1526
- T1580
Description
A machine learning job detected a significant spike in the rate of a particular failure in the GCP Audit messages. Spikes in failed messages may accompany attempts at privilege escalation, lateral movement, or discovery.
Detection logic
Spike in Azure Activity Logs Failed Messages
- source: elastic
- technicques:
- T1526
- T1580
Description
A machine learning job detected a significant spike in the rate of a particular failure in the Azure Activity Logs messages. Spikes in failed messages may accompany attempts at privilege escalation, lateral movement, or discovery.
Detection logic