Unexpected Removal of Sophos Firewall Rule
Last updated on:
Applies to: Log360Log360 Cloud
In this page
About the rule
Rule Type
Anomaly
Rule Description
Flags removal of firewall rules at unexpected times or by unknown users.
Severity
Attention
Rule Requirement
Criteria
Action1:
actionname = "Rule Deleted"
| isanomalous(User at an unusual Time)
| isanomalous(User with abnormal Count)
| isanomalous(Log source at an unusual Time)
| isanomalous(Log source with abnormal Count)
| isanomalous(Log source with unusual Username)
| isanomalous(User with unusual Log source)
select Action1.HOSTNAME,Action1.USERNAME,Action1.SOURCE_IP,Action1.RULENAME
Detection
Execution Mode
Intelligent
Log Sources
Sophos


