Box
Telemetry Evidence
These values show how indexed rules identify Box telemetry.Kusto
BoxEvents Panther
Box.Event box
Detection Rules
Kusto #
- Box - Abmormal user activity source medium: 'Detects spikes (deviations from avarage) in user activity.'
T1530 - Box - Executable file in folder source medium: 'Detects executable files in folders.'
T1189 - Box - File containing sensitive data source medium: 'Detects files which potentialy may contain sensitive data such as passwords, authentication tokens, secret keys.'
T1048 - Box - Forbidden file type downloaded source medium: 'Detects when new user downloads forbidden file types.'
T1189 - Box - Inactive user login source medium: 'Detects user login after long inactivity period.'
T1078 - Box - Item shared to external entity source medium: 'Detects when an item was shared to external entity.'
T1537 - Box - Many items deleted by user source medium: 'Detects when a user deletes many items in short period of time.'
T1485 - Box - New external user source medium: 'Detects when new user created with SourceLogin containing non-corporate domain.'
T1078 - Box - User logged in as admin source medium: 'Detects when user logged in as admin.'
T1078 - Box - User role changed to owner source medium: 'Detects when user collaboration role is changed to owner.'
T1078
Panther #
- Box Access Granted source low: A user granted access to their box account to Box technical support from account settings.
- Box Content Workflow Policy Violation source low: A user violated the content workflow policy.
- Box event triggered by unknown or external user source medium: An external user has triggered a box enterprise event.
T1567 - Box Large Number of Downloads source low: A user has exceeded the threshold for number of downloads within a single time frame.
T1567 - Box Large Number of Permission Changes source low: A user has exceeded the threshold for number of folder permission changes within a single time frame.
T1548 - Box New Login source informational: A user logged in from a new device.
T1078 - Box Shield Detected Anomalous Download Activity source high: A user's download activity has altered significantly.
T1567 - Box Shield Suspicious Alert Triggered source high: A user login event or session event was tagged as medium to high severity by Box Shield.
T1078 - Box Untrusted Device Login source informational: A user attempted to login from an untrusted device.
T1078 - Brute Force By IP source informational: An actor user was denied login access more times than the configured threshold.
T1110
Show 6 more
- Brute Force By User source informational: An actor user was denied login access more times than the configured threshold.
T1110 - GreyNoise V3 Malicious IP Activity source high: Detects when an IP address in any log event is classified as malicious or unknown by GreyNoise V3 internet scanner intelligence. Known business services and benign IPs are excluded.
T1595.001 - GTI/VirusTotal Threat Intelligence Indicator Match source high: Detects when an IP address, domain, or file hash in any log event matches a known malicious indicator from Google Threat Intelligence (GTI) / VirusTotal enrichment. Severity is elevated based on GTI's threat severity verdict and the number of vendors flagging the indicator as malicious.
T1595.001 - Malicious Content Detected source high: Box has detect malicious content, such as a virus.
T1204 - OTX Threat Intelligence Indicator Match source high: Detects when an IP address in any log event matches a known threat indicator from AlienVault OTX pulse intelligence. Severity is elevated when the pulse includes a named adversary or known malware families.
T1595.001 - Sign In from Rogue State source medium: Detects when an entity signs in from a nation associated with cyber attacks
T1078.004