LoFP LoFP / using an ip address that is shared by many users

Techniques

Sample rules

Sign-In From Malware Infected IP

Description

Indicates sign-ins from IP addresses infected with malware that is known to actively communicate with a bot server.

Detection logic

condition: selection
selection:
  riskEventType: malwareInfectedIPAddress