Sagan critical stable other
[CROWDSTRIKE] Initial Access Tactic Catchall
[CROWDSTRIKE] Initial Access Tactic Catchall
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[CROWDSTRIKE] Initial Access Tactic Catchall"; program:CrowdStrike; content:"tactic=Initial Access"; content:!"A stale endpoint became active"; content:!"A stale user became active"; content:!"A user accessed an IP associated with malicious activity"; content:!"A user performed a service access to an endpoint for the first time"; content:!"msg=A web-based activity was detected as anomalous by ML model"; content:!"msg=A user logged in to a machine for the first time"; content:!"A user accessed an unusual location"; content:!"IdpDetectionSummaryEvent"; parse_src_ip:1; normalize; reference:url,https://www.reddit.com/r/crowdstrike/comments/rbbzwi/pattern_disposition_values_in_detect_api/; classtype:trojan-activity; sid:5016651; rev:4; metadata:created_at 2025_06_25, updated_at 2026_03_26;) Field Validations
Loading…
Comments (0)
Loading comments...