Home
Advanced Threat Analytics (ATA)
All Rule Property Overrides in category: Advanced Threat Analytics (ATA)
ID
Management Pack Name
Management Pack Version
Microsoft.AdvancedThreatAnalytics.1_7.Center.AbnormalBehaviorSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.AbnormalSmbSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.AccountEnumerationSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.BruteForceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.ComputerPreauthenticationFailedSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.DirectoryServicesReplicationSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.DnsReconnaissanceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_GoldenTicket.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_OverpasstheHash.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.EncryptionDowngradeSuspiciousActivity_SkeletonKey.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.EnumerateSessionsSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.ForgedPacSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.HoneytokenActivitySuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.LdapSimpleBindCleartextPasswordSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.MassiveObjectDeletionSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.PassTheHashSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.PassTheTicketSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.RemoteExecutionSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.RetrieveDataProtectionBackupKeySuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_7.Center.SamrReconnaissanceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_7.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalBehaviorSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalProtocolSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalSensitiveGroupMembershipChangeSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.AbnormalVpnSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.AccountEnumerationSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.BruteForceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.ComputerPreauthenticationFailedSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.DirectoryServicesReplicationSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.DnsReconnaissanceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.EncryptionDowngradeSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.EnumerateSessionsSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.ForgedPacSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.GoldenTicketSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.HoneytokenActivitySuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.LdapBruteForceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.LdapCleartextPasswordSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.MassiveObjectDeletionSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.PassTheHashSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.PassTheTicketSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.RemoteExecutionSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.RetrieveDataProtectionBackupKeySuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_8.Center.SamrReconnaissanceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_8.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.AbnormalBehaviorSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.AbnormalProtocolSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.AbnormalSensitiveGroupMembershipChangeSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.AbnormalVpnSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.AccountEnumerationSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.BruteForceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.DirectoryServicesReplicationSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.DnsReconnaissanceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.EncryptionDowngradeSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.EnumerateSessionsSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.ForgedPacSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.GoldenTicketSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.HoneytokenActivitySuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.LdapBruteForceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.MaliciousServiceCreationSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.MassiveObjectDeletionSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.PassTheHashSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.PassTheTicketSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.RemoteExecutionSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.RetrieveDataProtectionBackupKeySuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0
Microsoft.AdvancedThreatAnalytics.1_9.Center.SamrReconnaissanceSuspiciousActivity.Override
Microsoft.AdvancedThreatAnalytics.1_9.Overrides
1.9.2.0