Cisco Secure Endpoint
Search Cisco Secure Endpoint rules.
Telemetry Evidence
These values show how indexed rules identify Cisco Secure Endpoint telemetry.Kusto
CiscoSecureEndpoint CiscoSecureEndpoint_CL
Detection Rules
Kusto #
- Cisco SE - Connection to known C2 server source high: 'This rule is triggered when connection to known C2 is detected from host.'
T1071 - Cisco SE - Dropper activity on host source high: 'Detects possible dropper activity on host.'
T1204,T1204.002 - Cisco SE - Generic IOC source high: 'This rule is triggered when generic IOC is observed on host.'
T1204,T1204.002 - Cisco SE - Malware execusion on host source high: 'Detects malware execution on host.'
T1204,T1204.002 - Cisco SE - Malware outbreak source high: 'Detects possible malware outbreak.'
T1133,T1190 - Cisco SE - Multiple malware on host source high: 'This rule triggers when multiple malware where detected on host.'
T1133,T1190 - Cisco SE - Policy update failure source medium: 'Detects policy updates failures.'
T1685 - Cisco SE - Possible webshell source high: 'Detects possible webshell on host.'
T1102 - Cisco SE - Ransomware Activity source high: 'This rule is triggered when possible ransomware activity is detected on host.'
T1486 - Cisco SE - Unexpected binary file source medium: 'Detects binary files in uncommon locations.'
T1133,T1190
Show 1 more
- Cisco SE High Events Last Hour source high: 'Find events from Cisco Secure Endpoint that are of High severity in the last hour.'
T1190,T1204,T1204.002
Compatible Rules
These rules declare Cisco Secure Endpoint connector or schema compatibility without a product-specific query filter.Kusto #
T1490T1547T1112, T1547T1685T1685T1027, T1059