Netskope
Telemetry Evidence
These values show how indexed rules identify Netskope telemetry.Kusto
NetskopeAlertEvents_CL NetskopeWebTransactions_CL NetskopeWebtxErrors_CL Panther
Netskope.Audit netskope
Detection Rules
Kusto #
- Netskope - Anomalous User Behavior (High Volume from Unmanaged Device) source medium: Detects anomalous user behavior including high data volume transfers from unmanaged devices, unusual access patterns, and suspicious application usage.
T1074,T1567 - Netskope - Data Movement Tracking (Upload/Download Monitoring) source informational: Tracks file uploads and downloads, monitoring data movement direction, size, and destination. Provides visibility into data flow patterns.
T1074,T1567 - Netskope - DLP Incident Spike source high: Detects a spike in Netskope DLP incidents within a short window. A sudden increase in DLP violations for a single user or DLP profile can indicate active data exfiltration, a misconfigured policy, or bulk handling of sensitive data. Triggers when a user generates more DLP incidents in the last hour than a configurable threshold.
T1530,T1567 - Netskope - Excessive Downloads Detection (Spike vs Baseline) source medium: Detects users with excessive download activity compared to their 7-day baseline. Triggers when current download volume exceeds 3x the average.
T1074,T1530 - Netskope - Heavy Personal Cloud Storage Usage (Shadow IT) source medium: Detects heavy usage of personal cloud storage applications like personal Dropbox, Google Drive, OneDrive personal, etc. Indicates potential Shadow IT or data leakage risk.
T1530,T1567 - Netskope - High Severity Alert source high: Detects Netskope alerts raised with a high or critical severity. High severity alerts typically indicate DLP violations, malware detections, compromised credentials, or significant policy breaches that warrant immediate investigation.
T1078,T1567 - Netskope - Impossible Travel Detection (Two Countries in Less Than 1 Hour) source high: Detects when a user accesses resources from two distinct countries within less than 1 hour, indicating potential credential compromise or VPN abuse.
T1078 - Netskope - Large Outbound Data Transfer / Sensitive Upload (DLP) source high: Detects large outbound data transfers and sensitive file uploads. Monitors for potential data exfiltration via cloud applications.
T1048,T1567 - Netskope - New Risky App Access vs 7-Day Baseline source medium: Compares today's accessed applications against a 7-day baseline and triggers alerts when users access new risky applications not seen before.
T1199,T1526 - Netskope - Repeated or Critical Policy Violations source high: Detects users with repeated policy violations or critical policy blocks. Monitors policy enforcement effectiveness and compliance.
T1048,T1685
Show 4 more
- Netskope - Suspicious Application Activity (Low Confidence / Risky App) source medium: Detects activity involving risky or low Cloud Confidence Level (CCL) applications, blocked application actions, or sensitive activities (upload, share, download) on unsanctioned apps. Helps surface Shadow IT and potential data leakage via risky cloud applications.
T1102,T1567 - Netskope - Suspicious Network Context (Unusual IPs/Geo/Ports) source medium: Detects suspicious network activity based on unusual source/destination IPs, geographic anomalies, uncommon ports, and high traffic volumes.
T1046,T1048,T1071 - Netskope - Unsanctioned/Risky Cloud App Access (Shadow IT) source medium: Alerts when users access unsanctioned or risky cloud applications based on Cloud Confidence Level (CCL) and app tags. Detects Shadow IT usage.
T1199,T1567 - Netskope - WebTransaction Error Detection source medium: 'Rule helps to track error occurred in Netskope WebTransaction Data Connector.'
T1204
Panther #
- Action Performed by Netskope Personnel source medium: An action was performed by Netskope personnel.
T1195 - Admin logged out because of successive login failures source medium: An admin was logged out because of successive login failures.
T1110 - An administrator account was created, deleted, or modified. source high: An administrator account was created, deleted, or modified.
T1098 - Netskope Many Objects Deleted source high: A user deleted a large number of objects in a short period of time.
T1485 - Netskope Many Unauthorized API Calls source high: Many unauthorized API calls were observed for a user in a short period of time.
T1110