Dark Web Breach Data

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects personal or sensitive organizational information exposed on dark web forums, marketplaces, and underground sites.

Severity

Critical

Rule Requirement

Criteria

Action1: actionname = "dark_web_breach_data" select Action1.SOURCETYPE,Action1.SOURCE,Action1.DOMAIN,Action1.EMAIL,Action1.PASSWORD,Action1.CATEGORY,Action1.SEVERITYLEVEL,Action1.CARD_NUMBER,Action1.USERNAME,Action1.ENCRYPTIONTYPE,Action1.CONFIDENCE_LEVEL,Action1.SERIALNUMBER,Action1.USERAGENT

Detection

Execution Mode

realtime

Log Sources

Advanced Threat Analytics