Samirbous
0165b97d30
[New] Suspected Lateral Movement from Compromised Host ( #5521 )
...
* [New] Suspected Lateral Movement from Compromised Host
Detects potential lateral movement or post-compromise activity by correlating alerts where the host.ip of one alert matches the source.ip of a subsequent alert. This behavior may indicate a compromised host being used to authenticate to another system or resource, including cloud services.
* Update multiple_alerts_by_host_ip_and_source_ip.toml
* Update multiple_alerts_by_host_ip_and_source_ip.toml
* Update multiple_alerts_by_host_ip_and_source_ip.toml
* Update multiple_alerts_by_host_ip_and_source_ip.toml
---------
Co-authored-by: Colson Wilhoit <48036388+DefSecSentinel@users.noreply.github.com >
2026-01-07 16:23:16 +00:00
..
2026-01-07 16:40:37 +01:00
2025-12-05 12:26:56 -06:00
2025-12-05 12:26:56 -06:00
2025-02-19 12:54:31 -03:00
2026-01-07 16:40:37 +01:00
2025-11-24 14:01:52 +00:00
2025-11-24 13:18:30 +00:00
2025-12-19 09:08:31 +00:00
2025-03-26 11:04:14 -04:00
2025-02-19 12:54:31 -03:00
2025-12-05 12:26:56 -06:00
2025-12-02 09:42:19 +01:00
2025-12-04 18:04:25 +00:00
2025-12-02 10:57:12 +00:00
2025-11-13 17:26:29 +00:00
2025-12-12 17:47:11 +00:00
2025-03-26 11:04:14 -04:00
2026-01-07 16:40:37 +01:00
2025-11-12 08:34:34 -03:00
2025-01-22 11:17:38 -06:00
2025-12-05 12:26:56 -06:00
2025-12-05 12:26:56 -06:00
2025-12-05 12:26:56 -06:00
2026-01-07 16:40:37 +01:00
2025-12-08 22:07:46 +05:30
2026-01-07 16:52:40 +01:00
2026-01-07 16:40:37 +01:00
2025-12-09 17:05:20 -08:00
2024-10-18 16:38:14 +02:00
2025-01-22 11:17:38 -06:00
2025-12-08 22:07:46 +05:30
2025-12-08 22:07:46 +05:30
2025-12-05 16:14:33 -05:00
2025-01-22 11:17:38 -06:00
2025-11-12 15:45:52 +01:00
2025-12-04 09:07:12 -05:00
2025-01-22 11:17:38 -06:00
2025-08-05 19:35:41 -04:00
2025-12-02 09:33:16 +01:00
2025-12-02 10:57:12 +00:00
2024-09-25 15:19:20 -05:00
2025-02-03 14:05:26 +01:00
2025-12-02 10:57:12 +00:00
2025-12-02 10:22:24 +01:00
2025-01-22 11:17:38 -06:00
2025-12-12 14:28:12 +00:00
2025-12-10 12:59:50 -05:00
2026-01-01 15:27:33 -03:00
2025-11-11 09:28:54 +00:00
2025-12-08 22:07:46 +05:30
2025-01-22 11:17:38 -06:00
2026-01-07 16:23:16 +00:00
2025-06-27 09:53:42 -03:00
2025-11-24 22:46:09 +05:30
2026-01-02 15:13:25 +00:00
2026-01-02 14:40:06 +00:00
2025-12-15 15:33:10 +00:00
2025-12-18 18:04:58 +00:00
2025-12-18 18:04:58 +00:00
2025-12-18 18:04:58 +00:00
2025-12-19 12:57:25 -03:00
2025-11-24 22:46:09 +05:30
2025-12-08 18:54:23 +05:30
2025-12-18 15:30:12 +00:00
2026-01-07 16:40:37 +01:00
2025-12-05 16:42:52 +01:00
2025-01-22 11:17:38 -06:00
2026-01-07 16:40:37 +01:00
2025-01-22 11:17:38 -06:00
2026-01-07 16:40:37 +01:00
2026-01-07 16:52:40 +01:00
2025-12-05 16:42:52 +01:00
2025-12-05 16:42:52 +01:00
2025-12-05 16:42:52 +01:00
2025-12-05 16:42:52 +01:00