Possible brute force attempted against user

This rule is part of a beta feature. To learn more, contact Support.
이 페이지는 아직 영어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우 언제든지 연락주시기 바랍니다.

Goal

Detect when a user attempts to access the OCI console an anomalous amount of times.

Strategy

This rule monitors OCI to detect the 404 error message.

Triage and response

  1. Determine if {{@user.name}} should be attempting to use the identified API calls: {{@evt.name}}.
  2. Contact the user to see if they intended to make these API calls.
  3. If the user did not make the API calls:
    • Rotate the credentials.
    • Investigate which unauthorized API calls might have succeeded throughout the rest of the environment.
PREVIEWING: esther/docs-11020-sheets-update