mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
19 lines
1.1 KiB
YAML
19 lines
1.1 KiB
YAML
name: Compromised User Account
|
|
id: 19669154-e9d1-4a01-b144-e6592a078092
|
|
version: 1
|
|
date: '2023-01-19'
|
|
author: Mauricio Velazco, Bhavin Patel, Splunk
|
|
description: Monitor for activities and techniques associated with Compromised User Account attacks.
|
|
narrative: Compromised User Account occurs when cybercriminals gain unauthorized access to accounts by using different techniques like brute force, social engineering, phishing & spear phishing, credential stuffing, etc. By posing as the real user, cyber-criminals can change account details, send out phishing emails, steal financial information or sensitive data, or use any stolen information to access further accounts within the organization. This analytic storic groups detections that can help security operations teams identify the potential signs of Compromised User Accounts.
|
|
references:
|
|
- https://www.proofpoint.com/us/threat-reference/compromised-account
|
|
tags:
|
|
analytic_story: Compromised User Account
|
|
category:
|
|
- Adversary Tactics
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Advanced Threat Detection
|