- Get Started with Threat Detection Management
- Analytics Rules
- Analytics Rule Classifications
- Create an Analytics Rule
- 1. Define the analytics rule
- 2. Import the analytics rule
- 3. Enable the analytics rule
- 4. Apply the analytics rule to your environment
- factFeature Analytics Rule JSON Configuration
- profiledFeature Analytics Rule JSON Configurationh
- contextFeature Analytics Rule JSON Configuration
- numericCountProfiledFeature Analytics Rule JSON Configuration
- numericDistinctCountProfiledFeature Analytics Rule JSON Configuration
- numericSumProfiledFeature Analytics Rule JSON Configuration
- Manage Analytics Rules
- Tune Analytics Rules
- Share Analytics Rules
- Troubleshoot Analytics Rules
- Analytics Rules Syntax
- Advanced Analytics Rule Syntax vs. Analytics Rule Syntax
- Logical Expressions in Analytics Rule Syntax
- String Operations Using Analytics Rule Syntax
- Integer Operations Using Analytics Rule Syntax
- Time Operations Using Analytics Rule Syntax
- Network Operations Using Analytics Rule Syntax
- Context Operations Using Analytics Rule Syntax
- Entity Operations Using Analytics Rule Syntax
- Correlation Rule Operations Using Analytics Rule Syntax
- Monitor the Analytics Engine
- Correlation Rules
- Threat Scoring
Analytics Rule Families
Get to know analytics rule families, categories of analytics rules organized by the type of event they evaluate.
Analytics rule families are a top-level classification that organizes analytics rules into 67 general categories. Each family describes the type of event the analytics rule evaluates; for example, authentication activity events or web activity events. Under each family, analytics rules are further classified into groups.
The family to which an analytics rule belongs affects the rarity score the analytics engine calculates when the analytics rule triggers. The analytics engine learns the pattern of triggers for each analytics rule family and learns to prioritize or de-prioritize certain families accordingly. If analytics rules in a family trigger very often, the analytics engine learns that these events are common and lowers the rarity score for analytics rule triggered in that family. If analytics rules in a family trigger seldomly, the analytics engine learns that these events are rare and increases the rarity score for analytics rule triggered in that family.
Family Name | Family ID | Description | Groups | Example Analytics Rules |
---|---|---|---|---|
Application Authentication Activity | app-auth-activity | Evaluates all events where authentication to an application has failed | Analytics rule groups under the Application Authentication Activity family |
|
Application Login Activity | app-login-activity | Evaluates all application logins | Analytics rule groups under the Application Login Activity family |
|
Audit Policy Modification Activity | audit-policy-mod | Evaluates all events where audit policies are modified | Analytics rule groups under the Audit Policy Modification Activity family |
|
Authentication Activity | auth-activity | Evaluates all events involving authentication | Analytics rule groups under the Authentication Activity family |
|
Bucket Creation Activity | bucket-creation-activity | Evaluates all events where cloud buckets are created | Analytics rule groups under the Bucket Creation Activity family |
|
Bucket Permission Modification Activity | bucket-permission-modification-activity | Evaluates all events where bucket permissions, policies, or access control lists (ACLs) are modified | Analytics rule groups under the Bucket Permission Modification Activity family |
|
Cloud Policy Management Activity | cloud-policy-management-activity | Evaluates all events where cloud policies are created, modified, or attached | Analytics rule groups under the Cloud Policy Management Activity family |
|
Compute Disk Activity | compute-disk-activity | Evaluates all events involving compute disk and volume | Analytics rule groups under the Compute Disk Activity family |
|
Compute Image Activity | compute-image-activity | Evaluates all events involving compute images | Analytics rule groups under the Compute Image Activity family |
|
Compute Snapshot Activity | compute-snapshot-activity | Evaluates all events involving compute snapshots | Analytics rule groups under the Compute Snapshot Activity family |
|
Compute Virtual Machine Activity | compute-vm-activity | Evaluates all events where compute instances are managed | Analytics rule groups under the Compute Virtual Machine Activity family |
|
Database Activity | database-activity | Evaluates all events where database is the subject |
| |
Database Query Activity | database-query-activity | Evaluates all events where databases are queried | Analytics rule groups under the Database Query Activity family |
|
Directory Service Activity | directory-service-activity | Evaluates all events that originated from a directory service or that are targeting directory service objects | Analytics rule groups under the Database Service Activity family |
|
Directory Service Object Write Activity | directory-service-object-write-activity | Evaluates all events where directory service objects are created or modified | Analytics rule groups under the Database Service Object Write Activity family |
|
DLL Load Activity | dll-load-activity | Evaluates all events where DLL image are loaded |
| |
DNS Activity | dns-activity | Evaluates all events involving DNS protocols |
| |
DNS Request Activity | dns-request-activity | Evaluates all events involving DNS requests |
| |
DNS Response Activity | dns-response-activity | Evaluates all events involving DNS responses | Analytics rule groups under the DNS Response Activity family |
|
Email Receive Activity | email-receive-activity | Evaluates events involving incoming email | Analytics rule groups under the Email Receive Activity family |
|
Email Rule Creation Activity | email-rule-create-activity | Evaluates all events where email rules are created | Analytics rule groups under the Email Rule Creation Activity family |
|
Email Send Activity | email-send-activity | Evaluates all events involving outgoing emails |
| |
Endpoint Login Activity | endpoint-login-activity | Evaluates all events involving endpoint logins | Analytics rule groups under the Endpoint Login Activity family |
|
Endpoint Login Activity - NAC | endpoint-login-activity-nac | Evaluates all events where endpoint logins originate from a network access application | Analytics rule groups under the Endpoint Login Activity - NAC family |
|
Endpoint Screenshot Activity | endpoint-screenshot-activity | Evaluates all events involving endpoint screenshots | Analytics rule groups under the Endpoint Screenshot Activity family |
|
File Activity | file-activity | Evaluates all file events |
| |
File Delete Activity | file-delete-activity | Evaluates all events where files are deleted |
| |
File Download Activity | file-download-activity | Evaluates all events where files are downloaded | Analytics rule groups under the File Download Activity family |
|
File Permission Modification Activity | file-permission-modify-activity | Evaluates all events where file permissions are modified | Analytics rule groups under the File Permission Modification Activity family |
|
File Read Activity | file-read-activity | Evaluates all events where files are read |
| |
File Upload Activity | file-upload-activity | Evaluates all events where files are uploaded |
| |
File Write Activity | file-write-activity | Evaluates all file write events |
| |
File Write Activity – USB | file-write-activity-usb | Evaluates all events where files are written to a USB device | Analytics rule groups under the File Write Activity - USB family |
|
General Activity | general-activity | Evaluates ALL events |
| |
Group Member Addition Activity | group-member-addition-activity | Evaluates all events where members are added to groups | Analytics rule groups under the Group Member Addition Activity family |
|
Log Clear Activity | log-clear-activity | Evaluates all log clear events |
| |
Login Activity | login-activity | Evaluates all login events |
| |
Mailbox Permission Modification Activity | mailbox-permission-modification-activity | Evaluates events where mailbox permissions are modified | Analytics rule groups under the Mailbox Permission Modification Activity family |
|
Network Activity | network-activity | Evaluates all network events |
| |
Password Checkout Activity | password-checkout-activity | Evaluates all all vault password checkout events | Analytics rule groups under the Password Checkout Activity family |
|
Physical Location Access Activity | physical-location-access-activity | Evaluates all events involving access to physical locations | Analytics rule groups under the Physical Location Access Activity family |
|
Privilege Use Activity | privilege-use-activity | Evaluates all privilege use activity | Analytics rule groups under the Privilege Use Activity family |
|
Process Creation Activity | process-creation-activity | Evalautes all events where processes are executed | Analytics rule groups under the Process Creation Activity family |
|
Registry Activity | registry-activity | Evaluates all registry events |
| |
Role Assumption Activity | role-assume-activity | Evaluates all events where roles are assumed | Analytics rule groups under the Role Assumption Activity family |
|
Role Permission Modification | role-permission-modification-activity | Evaluates all events where role permissions are modified | Analytics rule groups under the Role Permission Modification family |
|
Role Creation and Modification Activity | role-write-activity | Evaluates all events where roles are created or modified | Analytics rule groups under the Role Creation and Modification Activity family |
|
Rule Delete Activity | rule-delete-activity | Evaluates all events where security rules are deleted |
| |
Scheduled Tasks Creation Activity | scheduled-task-creation-activity | Evaluates all events where scheduled tasks are created | Analytics rule groups under the Scheduled Tasks Creation Activity family |
|
Script Execution Activity – PowerShell | script-execution-activity | Evaluates all events involving PowerShell scripts and invocations | Analytics rule groups under the Script Execution Activity – PowerShell family |
|
Security Alerts | security-alerts | Evaluates all events where alerts are triggered |
| |
Security Alerts – DLP | security-alerts-dlp | Evaluates all events involving DLP alerts | Analytics rule groups under the Security Alerts - DLP family |
|
Share Access Activity | share-access-activity | Evaluates all events where access is shared | Analytics rule groups under the Share Access Activity family |
|
USB Activity | usb-activity | Evaluates all events that occurred on or in peripheral devices |
| |
User Activity | user-activity | Evaluates all user events |
| |
User Creation Activity | user-creation-activity | Evaluates all events where users are created | Analytics rule groups under the User Creation Activity family |
|
User Deletion Activity | user-deletion-activity | Evaluates all events where users are deleted |
| |
User Key Creation Activity | user-key-creation-activity | Evaluates all events where user associated keys are created |
| |
User Lock Activity | user-lock-activity | Evaluates all user lockdown events |
| |
User Password Modification Activity | user-password-modification-activity | Evaluates all events where user account passwords are modified | Analytics rule groups under the User Password Modification Activity family |
|
User Switch Activity | user-switch-activity | Evaluates all events where a user switches identities |
| |
VPN Login Activity | vpn-login-activity | Evaluates all events involving VPN logins |
| |
VPN Logout Activity | vpn-logout-activity | Evaluates all events involving VPN logouts |
| |
Web Activity | web-activity | Evaluates all events involving web protocols |
| |
Web Meeting Activity | web-meeting-activity | Evaluates all events where a web meeting is the subject |
| |
Web Request Activity | web-request-activity | Evaluates all events involving HTTP requests |
| |
Windows Service Creation Activity | windows-service-creation-activity | Evaluates all events where a Windows system service is created | Analytics rule groups under the Windows Service Creation family |
|