Both Falcon ITDR modules provide visibility to “rogue credential” or behavior anomalies:
• Access from a forbidden country
• Adding a user to a privileged group
• Anomalous DCE/RPC
• Bronze Bit (CVE-2020-17049)
• Custom threat detection using policy rules
• Excessive access (servers)
• Excessive access (services)
• Excessive access (workstations)
• Hidden object detected
• Identity verification denied
• Identity verification timeout
• Service account misuse
• Suspicious VPN connections — unusual user geolocation
• Unusual access to a server
• Unusual access to a service
• Unusual protocol implementation
• Usage of IP with a bad reputation
• Use of stale endpoint
• Access from a forbidden country
• Adding a user to a privileged group
• Anomalous DCE/RPC
• Bronze Bit (CVE-2020-17049)
• Custom threat detection using policy rules
• Excessive access (servers)
• Excessive access (services)
• Excessive access (workstations)
• Hidden object detected
• Identity verification denied
• Identity verification timeout
• Service account misuse
• Suspicious VPN connections — unusual user geolocation
• Unusual access to a server
• Unusual access to a service
• Unusual protocol implementation
• Usage of IP with a bad reputation
• Use of stale endpoint