Sagan critical stable other

[CROWDSTRIKE] Initial Access Tactic Catchall

[CROWDSTRIKE] Initial Access Tactic Catchall

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Initial Access Tactic Catchall"; program:CrowdStrike; content:"tactic=Initial Access"; content:!"A stale endpoint became active"; content:!"A stale user became active"; content:!"A user accessed an IP associated with malicious activity"; content:!"A user performed a service access to an endpoint for the first time"; content:!"msg=A web-based activity was detected as anomalous by ML model"; content:!"msg=A user logged in to a machine for the first time"; content:!"A user accessed an unusual location"; content:!"IdpDetectionSummaryEvent"; parse_src_ip:1; normalize; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016651; rev:4; metadata:created_at 2025_06_25, updated_at 2026_03_26;)

Field Validations

Loading…

Comments (0)

Loading comments...