Skip to main content
Skip table of contents

ASD – Requirements


Control NameRulesAIE AlertsInvestigationsSummary ReportsDetailed Reports
1526CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0120CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0125




0133CCF: Corroborated Data Access Anomalies
CCF: Excessive Authentication Failure
CCF: Account Modification
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: FIM Abnormal Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Applications Accessed By User Inv
CCF: Excessive Authentication Failure Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Time Sync Error Inv
CCF: Applications Accessed By User Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: User Object Access Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary

1213CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0138CCF: Config Modified
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Backup Information
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: FIM Delete Activity Alarm
CCF: Denial Of Service Alarm
CCF: Blacklisted Account Alarm
CCF: Backup Failure Alarm
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Backup Activity Inv
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Critical Environment Error Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: Backup Activity Summary

0123CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1053CCF: Excessive Authentication FailureCCF: Priv Group Access Granted AlarmCCF: Physical Access Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: Physical Access Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary

1074CCF: Excessive Authentication FailureCCF: Priv Group Access Granted AlarmCCF: Physical Access Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: Physical Access Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary

0157CCF: Abnormal Origin Location
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Early TLS/SSL Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: GeoIP Inv
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: GeoIP Summary

1296

CCF: Physical Access InvCCF: Physical Access Summary
1503CCF: Corroborated Data Access Anomalies
CCF: Excessive Authentication Failure
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Unknown User Account Alarm
CCF: Blacklisted Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: FIM Delete Activity Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Host Access Granted And Revoked Inv
CCF: Applications Accessed By User Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Password Modification Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Applications Accessed By User Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0409CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0411CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0816CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1508CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0445CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1509CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Config Modified
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1175CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP Blacklisted Region Activity
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Blacklisted Account Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Excessive Authentication Failure Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

0446CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0447CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0448CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0430CCF: Corroborated Data Access Anomalies
CCF: Excessive Authentication Failure
CCF: Account Modification
CCF: Account Disabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Unknown User Account Alarm
CCF: Blacklisted Account Alarm
CCF: Host Access Granted And Revoked Inv
CCF: Applications Accessed By User Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: User Object Access Inv
CCF: Applications Accessed By User Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: User Object Access Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1404CCF: Corroborated Data Access Anomalies
CCF: Excessive Authentication Failure
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Unknown User Account Alarm
CCF: Blacklisted Account Alarm
CCF: Host Access Granted And Revoked Inv
CCF: Applications Accessed By User Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: User Object Access Inv
CCF: Applications Accessed By User Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: User Misuse Summary
CCF: User Object Access Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0407CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0441CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0443CCF: Account Modification
CCF: Account Enabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Local Account Created and Used
CCF: Corroborated Data Access Anomalies
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0078CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Enabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Enabled Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0854CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Enabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Enabled Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0553CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0555CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
1019




0313CCF: FIM Abnormal Activity
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity AlarmCCF: LogRhythm Data Loss Defender Log InvCCF: LogRhythm Data Loss Defender Log Summary
0311CCF: FIM Abnormal Activity
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity AlarmCCF: LogRhythm Data Loss Defender Log InvCCF: LogRhythm Data Loss Defender Log Summary
0342CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Denial Of Service Alarm
CCF: Time Sync Error Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: Time Sync Error Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary
CCF: User Object Access Summary

1069CCF: FIM Abnormal Activity
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity AlarmCCF: LogRhythm Data Loss Defender Log InvCCF: LogRhythm Data Loss Defender Log Summary
1469CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0414CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP SummaryCCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1538CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0420CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0975CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0415CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: GeoIP Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: GeoIP Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

1403CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Auth After Numerous Failed Auths
CCF: Excessive Authentication Failure
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0431CCF: Excessive Authentication Failure
CCF: Account Disabled
CCF: Account Enabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Auth After Numerous Failed Auths
CCF: Distributed Brute Force

CCF: Excessive Authentication Failure Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Auth Failure Summary
CCF: Account Modified Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary

1402CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Unknown User Account Alarm
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: User Object Access Inv

CCF: Unknown User Account Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Object Access Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1380CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1473CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1382CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1387




1144CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
0940CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
1472CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
1494CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
1495CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
1496CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
0300CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary

0298CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary

1497CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

1500CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

1211CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

0115CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary

1510CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Denial Of Service Alarm
CCF: Blacklisted Account Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary

1511CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Denial Of Service Alarm
CCF: Blacklisted Account Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary

1514CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary

0580CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1405CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0988
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Inv
CCF: Audit Log Inv
CCF: Time Sync Error Summary
CCF: Audit Log Summary

0584CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Blacklist Location Auth
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: Priv Authentication Activity Summary
CCF: Applications Accessed By User Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Term Account Activity Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0582CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1536CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1537CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0585CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0586CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Denial Of Service Alarm
CCF: Time Sync Error Alarm
CCF: Blacklisted Account Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: Time Sync Error Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary

0859CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary

0991CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary

0109CCF: Config Modified
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Audit Log Summary
CCF: Time Sync Error Summary

1228CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1422CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1277
CCF: Early TLS/SSL Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Use Of Non-Encrypted Protocols InvCCF: Use Of Non-Encrypted Protocols Summary
1262CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP SummaryCCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1261CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1263CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1264CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1256CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Denial Of Service Alarm
CCF: Time Sync Error Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: Time Sync Error Inv
CCF: GeoIP Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary
CCF: GeoIP Summary
CCF: User Object Access Summary

1255CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Denial Of Service Alarm
CCF: Time Sync Error Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: Time Sync Error Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary
CCF: User Object Access Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1268CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Config Modified
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1182#N/A#N/A#N/A#N/A#N/A
1301
CCF: Rogue Access Point AlarmCCF: Rogue Access Point InvCCF: Rogue Access Point Summary
1435
CCF: Denial Of Service AlarmCCF: Denial Of Service Inv

1139
CCF: Early TLS/SSL Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Rogue Access Point Inv
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Rogue Access Point Summary

0670CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail


Control NameRulesAIE AlertsInvestigationsSummary ReportsDetailed Reports
1526CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0120CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0125




0133CCF: Corroborated Data Access Anomalies
CCF: Excessive Authentication Failure
CCF: Account Modification
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: FIM Abnormal Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Applications Accessed By User Inv
CCF: Excessive Authentication Failure Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Time Sync Error Inv
CCF: Applications Accessed By User Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: User Object Access Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary

1213CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0138CCF: Config Modified
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Backup Information
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: FIM Delete Activity Alarm
CCF: Denial Of Service Alarm
CCF: Blacklisted Account Alarm
CCF: Backup Failure Alarm
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Backup Activity Inv
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Critical Environment Error Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: Backup Activity Summary

0123CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1053CCF: Excessive Authentication FailureCCF: Priv Group Access Granted AlarmCCF: Physical Access Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: Physical Access Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary

1074CCF: Excessive Authentication FailureCCF: Priv Group Access Granted AlarmCCF: Physical Access Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: Physical Access Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary

0157CCF: Abnormal Origin Location
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Early TLS/SSL Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: GeoIP Inv
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: GeoIP Summary

1296

CCF: Physical Access InvCCF: Physical Access Summary
1503CCF: Corroborated Data Access Anomalies
CCF: Excessive Authentication Failure
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Unknown User Account Alarm
CCF: Blacklisted Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: FIM Delete Activity Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Host Access Granted And Revoked Inv
CCF: Applications Accessed By User Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Password Modification Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Applications Accessed By User Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0409CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0411CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0816CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1508CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0445CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1509CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Config Modified
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1175CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP Blacklisted Region Activity
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Blacklisted Account Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Excessive Authentication Failure Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

0446CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0447CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0448CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0430CCF: Corroborated Data Access Anomalies
CCF: Excessive Authentication Failure
CCF: Account Modification
CCF: Account Disabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Unknown User Account Alarm
CCF: Blacklisted Account Alarm
CCF: Host Access Granted And Revoked Inv
CCF: Applications Accessed By User Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: User Object Access Inv
CCF: Applications Accessed By User Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: User Object Access Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1404CCF: Corroborated Data Access Anomalies
CCF: Excessive Authentication Failure
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Unknown User Account Alarm
CCF: Blacklisted Account Alarm
CCF: Host Access Granted And Revoked Inv
CCF: Applications Accessed By User Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: User Object Access Inv
CCF: Applications Accessed By User Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: User Misuse Summary
CCF: User Object Access Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0407CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0441CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0443CCF: Account Modification
CCF: Account Enabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Local Account Created and Used
CCF: Corroborated Data Access Anomalies
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0078CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Enabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Enabled Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0854CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Enabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Enabled Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0553CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0555CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
1019




0313CCF: FIM Abnormal Activity
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity AlarmCCF: LogRhythm Data Loss Defender Log InvCCF: LogRhythm Data Loss Defender Log Summary
0311CCF: FIM Abnormal Activity
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity AlarmCCF: LogRhythm Data Loss Defender Log InvCCF: LogRhythm Data Loss Defender Log Summary
0342CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Denial Of Service Alarm
CCF: Time Sync Error Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: Time Sync Error Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary
CCF: User Object Access Summary

1069CCF: FIM Abnormal Activity
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: FIM Delete Activity AlarmCCF: LogRhythm Data Loss Defender Log InvCCF: LogRhythm Data Loss Defender Log Summary
1469CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0414CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP SummaryCCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1538CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0420CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0975CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0415CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Blacklisted Account Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: GeoIP Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: GeoIP Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

1403CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Auth After Numerous Failed Auths
CCF: Excessive Authentication Failure
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP Summary
0431CCF: Excessive Authentication Failure
CCF: Account Disabled
CCF: Account Enabled
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Auth After Numerous Failed Auths
CCF: Distributed Brute Force

CCF: Excessive Authentication Failure Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Auth Failure Summary
CCF: Account Modified Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary

1402CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Unknown User Account Alarm
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: User Object Access Inv

CCF: Unknown User Account Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Object Access Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1380CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1473CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1382CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1387




1144CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
0940CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
1472CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
1494CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
1495CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
1496CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Critical Event After Attack
CCF: Distributed Brute Force
CCF: External Brute Force Auths
CCF: Abnormal Amount of Data Transferred
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Config Change After Attack
CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Compromises Detected Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Denial Of Service Alarm
CCF: Unknown User Account Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Compromises Detected Inv
CCF: Suspected Wireless Attack Inv
CCF: Denial Of Service Inv
CCF: Suspicious Users Inv
CCF: Malware Detected Inv
CCF: Vulnerability Detected Inv
CCF: GeoIP Inv
CCF: Unknown User Account Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Compromises Detected Summary
CCF: Suspected Wireless Attack Summary
CCF: Malware Detected Summary
CCF: Vulnerability Detected Summary
CCF: Top Suspicious Users
CCF: Unknown User Account Detail
0300CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary

0298CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary

1497CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

1500CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

1211CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary

0115CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: PRD Envir Config/Policy Change Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Signature Activity Inv
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary

1510CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Denial Of Service Alarm
CCF: Blacklisted Account Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary

1511CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Denial Of Service Alarm
CCF: Blacklisted Account Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary

1514CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary

0580CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1405CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0988
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Inv
CCF: Audit Log Inv
CCF: Time Sync Error Summary
CCF: Audit Log Summary

0584CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Blacklist Location Auth
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: Priv Authentication Activity Summary
CCF: Applications Accessed By User Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Term Account Activity Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
0582CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1536CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1537CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0585CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
0586CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Denial Of Service Alarm
CCF: Time Sync Error Alarm
CCF: Blacklisted Account Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: Time Sync Error Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary
CCF: GeoIP Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary

0859CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary

0991CCF: Data Loss Prevention
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Corroborated Data Access Anomalies
CCF: Backup Information
CCF: Backup Failure Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Denial Of Service Alert
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Backup Activity Inv
CCF: Time Sync Error Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Backup Activity Summary
CCF: Time Sync Error Summary

0109CCF: Config Modified
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Audit Log Summary
CCF: Time Sync Error Summary

1228CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Excessive Authentication Failure
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
1422CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1277
CCF: Early TLS/SSL Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Use Of Non-Encrypted Protocols InvCCF: Use Of Non-Encrypted Protocols Summary
1262CCF: Corroborated Account Anomalies
CCF: Corroborated Data Access Anomalies
CCF: Abnormal Origin Location
CCF: GeoIP Blacklisted Region Activity
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Same User
CCF: Blacklisted Account AlarmCCF: GeoIP InvCCF: GeoIP SummaryCCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1261CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1263CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1264CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1256CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Denial Of Service Alarm
CCF: Time Sync Error Alarm
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: Time Sync Error Inv
CCF: GeoIP Inv
CCF: User Object Access Inv
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary
CCF: GeoIP Summary
CCF: User Object Access Summary

1255CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: FIM Delete Activity Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Denial Of Service Alarm
CCF: Time Sync Error Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Object Access Inv
CCF: Audit Log Inv
CCF: Critical Environment Error Inv
CCF: Denial Of Service Inv
CCF: Time Sync Error Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Object Access Summary
CCF: Audit Log Summary
CCF: Critical Environment Error Summary
CCF: Time Sync Error Summary
CCF: User Object Access Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1268CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Excessive Authentication Failure
CCF: Corroborated Data Access Anomalies
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Account Modification
CCF: Account Deleted
CCF: Account Disabled
CCF: Account Enabled
CCF: Social Media Event
CCF: Disabled Account Auth Success
CCF: Corroborated Account Anomalies
CCF: Misuse
CCF: Local Account Created and Used
CCF: Config Modified
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: Unknown User Account Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Time Sync Error Alarm
CCF: Password Modification Inv
CCF: Applications Accessed By User Inv
CCF: Privileged Account Modification Inv
CCF: Privileged Account Escalation Inv
CCF: GeoIP Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: Host Access Granted And Revoked Inv
CCF: Excessive Authentication Failure Inv
CCF: Account Modified Inv
CCF: Account Deleted Inv
CCF: Account Disabled Inv
CCF: Account Enabled Inv
CCF: Social Media Inv
CCF: User Misuse Inv
CCF: Unknown User Account Inv
CCF: Audit Log Inv
CCF: Time Sync Error Inv
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Applications Accessed By User Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: User Priv Escalation (Windows) Summary
CCF: GeoIP Summary
CCF: User Object Access Summary
CCF: Top Suspicious Users
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Account Deleted Summary
CCF: Account Disabled Summary
CCF: Account Enabled Summary
CCF: Social Media Summary
CCF: User Misuse Summary
CCF: Audit Log Summary
CCF: Time Sync Error Summary
CCF: Host Access Granted And Revoked Detail
CCF: Unknown User Account Detail
1182#N/A#N/A#N/A#N/A#N/A
1301
CCF: Rogue Access Point AlarmCCF: Rogue Access Point InvCCF: Rogue Access Point Summary
1435
CCF: Denial Of Service AlarmCCF: Denial Of Service Inv

1139
CCF: Early TLS/SSL Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Rogue Access Point Inv
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Rogue Access Point Summary

0670CCF: Misuse
CCF: Social Media Event
CCF: Corroborated Account Anomalies
CCF: Disabled Account Auth Success
CCF: External Brute Force Auths
CCF: Local Account Created and Used
CCF: Password Modified by Admin
CCF: Admin Password Modified
CCF: Multiple Account Passwords Modified by Admin
CCF: Password Modified by Another User
CCF: Account Enabled
CCF: Account Disabled
CCF: Account Deleted
CCF: Account Modification
CCF Excessive Authentication Failure
CCF: FIM Abnormal Activity
CCF: FIM Add Activity
CCF: FIM General Activity
CCF: Data Loss Prevention
CCF: Backup Information
CCF: GeoIP General Activity
CCF: GeoIP Blacklisted Region Activity
CCF: Corroborated Data Access Anomalies
CCF: Config Modified
CCF: Software Install
CCF: Software Uninstall
CCF: FIM Information
CCF: Abnormal Amount of Data Transferred
CCF: Large Outbound Transfer
CCF: Linux sudo Privilege Escalation
CCF: Windows RunAs Privilege Escalation
CCF: Abnormal Origin Location
CCF: Attack then External Connection
CCF: Auth After Numerous Failed Auths
CCF: Auth After Security Event
CCF: Blacklist Location Auth
CCF: Concurrent VPN from Multiple Locations
CCF: Concurrent VPN from Single User
CCF: Config Change After Attack
CCF: Config Change then Critical Error
CCF: Config Deleted/Disabled
CCF: Critical Event After Attack
CCF: Data Destruction
CCF: Data Exfiltration Observed
CCF: Distributed Brute Force
CCF: Unknown User Account Alarm
CCF: Priv Group Access Granted Alarm
CCF: Privilege Escalation After Attack Alarm
CCF: Blacklisted Account Alarm
CCF: FIM Delete Activity Alarm
CCF: PRD Envir Config/Policy Change Alarm
CCF: Time Sync Error Alarm
CCF: Audit Logging Stopped Alarm
CCF: Audit Log Cleared Alarm
CCF: Failed Audit Log Write Alarm
CCF: Software Install Fail Alarm
CCF: Software Uninstall Fail Alarm
CCF: LogRhythm Silent Log Source Error Alarm
CCF: Early TLS/SSL Alarm
CCF: Backup Failure Alarm
CCF: Critical/PRD Envir Patch Failure Alarm
CCF: PRD Envir Signature Failure Alarm
CCF: Non-Encrypted Protocol Alarm
CCF: Rogue Access Point Alarm
CCF: Suspected Wireless Attack Alarm
CCF: Compromises Detected Alarm
CCF: Malware Alarm
CCF: Vulnerability Detected Alarm
CCF: Denial Of Service Alarm
CCF: User Misuse Inv
CCF: Social Media Inv
CCF: Unknown User Account Inv
CCF: Privileged Account Modification Inv
CCF: Account Enabled Inv
CCF: Account Disabled Inv
CCF: Account Deleted Inv
CCF: Account Modified Inv
CCF Excessive Authentication Failure Inv
CCF: Password Modification Inv
CCF: Object Access Inv
CCF: Suspicious Users Inv
CCF: User Object Access Inv
CCF: GeoIP Inv
CCF: Backup Activity Inv
CCF: LogRhythm Data Loss Defender Log Inv
CCF: Config/Policy Change Inv
CCF: Patch Activity Inv
CCF: Time Sync Error Inv
CCF: Signature Activity Inv
CCF: Audit Log Inv
CCF: Applications Accessed By User Inv
CCF: Critical Environment Error Inv
CCF: Use Of Non-Encrypted Protocols Inv
CCF: Compromises Detected Inv
CCF: Host Access Granted And Revoked Inv
CCF: Rogue Access Point Inv
CCF: Suspected Wireless Attack Inv
CCF: Privileged Account Escalation Inv
CCF: Malware Detected Inv
CCF: Physical Access Inv
CCF: Vulnerability Detected Inv
CCF: Denial Of Service Inv
CCF: User Misuse Summary
CCF: Social Media Summary
CCF: Priv Authentication Activity Summary
CCF: Priv Account Management Activity Summary
CCF: Account Enabled Summary
CCF: Account Disabled Summary
CCF: Account Deleted Summary
CCF: Account Modified Summary
CCF: Term Account Activity Summary
CCF: Auth Failure Summary
CCF: Access Failure Summary
CCF: Auth Success Summary
CCF: Access Success Summary
CCF: Object Access Summary
CCF: Top Suspicious Users
CCF: User Object Access Summary
CCF: GeoIP Summary
CCF: Backup Activity Summary
CCF: LogRhythm Data Loss Defender Log Summary
CCF: Config/Policy Change Summary
CCF: Patch Activity Summary
CCF: Time Sync Error Summary
CCF: Signature Activity Summary
CCF: Audit Log Summary
CCF: Applications Accessed By User Summary
CCF: Critical Environment Error Summary
CCF: Use Of Non-Encrypted Protocols Summary
CCF: Compromises Detected Summary
CCF: Rogue Access Point Summary
CCF: Suspected Wireless Attack Summary
CCF: User Priv Escalation (Windows) Summary
CCF: User Priv Escalation (SU & SUDO) Summary
CCF: Malware Detected Summary
CCF: Physical Access Summary
CCF: Vulnerability Detected Summary
CCF: Unknown User Account Detail
CCF: Host Access Granted And Revoked Detail
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.