Forum Discussion

wootts's avatar
wootts
Iron Contributor
Aug 17, 2021

Watchlists and Hunting

Hi all - reaching out to see if there are any practical use cases for the new watchlists etc, such as terminated / notified user - to get the best out of the data - while I see easy use cases for IP addresses - users and machines seem to have very little written (accepting early days for the new templates) any suggestions / good sources
  • GaryBushey's avatar
    GaryBushey
    Bronze Contributor

    wootts The High Value assets can be used in a couple of different ways.  One that comes to mind is if there is any incident against an asset that is part of the list, raise the severity (either inside the Analytic rule or by using a Playlist).  Another is to check to see if anyone is performing queries against entries in this list (assuming you have the query monitoring enabled) to make sure people are not looking for information they shouldn't (we had a list like this at a hospital I used to work at to make sure people were not looking up information for celebrities we were treating)

     

    The Service Accounts list could be used to ignore incidents from service accounts, as there are usually quite a few of them, or lower the severity.

     

    Terminated employees is very useful to keep a better eye on their activities, again by raising the severity.

    • wootts's avatar
      wootts
      Iron Contributor
      as always gary - great help - will start with building some and see where it takes me - thanks alot

Resources