All Breach Data

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Consolidated detection combining dark web exposures, botnet leaks, and supply chain breaches for comprehensive breach monitoring.

Severity

Critical

Rule Requirement

Criteria

Action1: actionname = "all_breach_data" select Action1.SOURCETYPE,Action1.SOURCE,Action1.DOMAIN,Action1.EMAIL,Action1.PASSWORD,Action1.CATEGORY,Action1.SEVERITYLEVEL,Action1.CARD_NUMBER,Action1.USERNAME,Action1.ENCRYPTIONTYPE,Action1.CONFIDENCE_LEVEL,Action1.SERIALNUMBER,Action1.USERAGENT,Action1.IPADDRESS

Detection

Execution Mode

realtime

Log Sources

Advanced Threat Analytics