LoFP LoFP / user using a vpn or proxy

Techniques

Sample rules

Activity from Anonymous IP Addresses

Description

Detects when a Microsoft Cloud App Security reported when users were active from an IP address that has been identified as an anonymous proxy IP address.

Detection logic

condition: selection
selection:
  eventName: Activity from anonymous IP addresses
  eventSource: SecurityComplianceCenter
  status: success