Sagan medium stable other

[CROWDSTRIKE] IdpDetectionSummaryEvent - Catch All

[CROWDSTRIKE] IdpDetectionSummaryEvent - Catch All

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] IdpDetectionSummaryEvent - Catch All"; program:CrowdStrike; content:"IdpDetectionSummaryEvent"; content:!"msg=A stale user became active"; content:!"msg=A user accessed an IP associated with malicious activity"; content:!"msg=A user executed a self-request for a Ticket Granting Service (TGS), following a Kerberos certificate-based authentication, which might indicate a malicious activity"; parse_src_ip: 1; normalize; classtype:suspicious-activity; sid:5017320; rev:1; metadata:created_at 2025_12_02;)

Field Validations

Loading…

Comments (0)

Loading comments...