Detection Models
Linux anomalous network activityWindows anomalous network activityWindows anomalous process all hostsWindows anomalous user nameWindows rare process by hostHigh count network denies (outbound traffic)Unusual amount of outbound traffic (Data leak)Many logins OK from same IPExcessive Failed Logins for a Single UserUser Behaviour Analytics on Active Directory (ADUBA)DGA DetectionAnomalous User Name in Active DirectoryDetection of silenced data sourcesRare destination Country detectionBrute force Login DetectionMany Logins OK from the same IPAWS CloudTrail rare Method for a CityAWS CloudTrail rare Method for a CountryAWS CloudTrail rare Method for a UserAnomalous denied traffic detectionAnomalous outbound trafficAWS CloudTrail rare error CodeAWS CloudTrail rare error MessageAWS CloudTrail High distinct count error CodeAWS CloudTrail High distinct count error MessageData Leak DetectionLogon Spike DetectionSuspicious Referring WebsitesAnomalies in SalesFolder searches