Rules read like detections and map to the techniques they catch.
The rule that catches it was written before you needed it, and it arrives with its technique attached.
Detect, threat detection
- 02:14criticalAdversary-in-the-middle session hijack detected
- 02:28criticalLogin locations requiring supersonic speed
- 02:33highMultiple MFA failures then MFA success
- 02:39criticalUser granted consent to unverified publisher application
- 02:44criticalInbox rule created to forward email to external domain
- criticalFailed logins from single IP across multiple users
- highAdded credentials to existing service principal
The attack does not look like an attack until you already know what to look for.
How it works
Rules are authored in a Sigma-compatible schema and versioned like code, legible to anyone who has read a detection before
Single events, thresholds, anomalies, correlations and baseline deviations, because the attacks do not all have the same shape
Mapped to MITRE ATT&CK, with false-positive and exclusion blocks for tuning against your own environment
Ask the specialist that owns this work.
Ask in your own words. The Threat Triage Agent runs as you, and any action it can take ships off until an admin turns it on.
Threat Triage Agent
Groups related alerts into one investigation and tells you which of them are justified benign noise.
- You asked: Is the alert on Jaime Rivera worth waking someone for?
Nuvio answered: The five alerts on Jaime Rivera inside thirty minutes are one chain. I merged them into one investigation and put it first in your queue.
Ready for youOpen INC-1107
Detect, investigations