
The L1-Entity Monitoring - Indicators and Warnings package is designed to identify anomalies dealing with account authentication and management. This package has to be integrated with any Product packages that track account activities. This package could also be integrated with but does not require, the L2-Entity Monitoring-Situational and Awareness package for further detection and investigations.

The idea to have the L1-Entity Monitoring Indicators and Warnings package is to build some common functionality (such as Rules) that can be applied to multiple Product packages. Wherever possible, only the filters will reside within the product packages. Those filters in the product package will then be linked into an OR statement in the null (false) L1 package filter where appropriate.

Minimum Requirements

Suggested apps

Suggested for you are based on app category, product compatibility, popularity, rating and newness. Some apps may not show based on entitlements. Learn more about entitlements.


L1-Entity Monitoring - Indicators and Warnings
30.1 KB
Nov 26, 2019
More info Less info
Product compatibility
Version 6.8 · 6.11.0 · 6.9.1
Version 7.0 · 7.2 · 7.3 · 7.4 · 7.5 · 7.6 · 7.7 · 7.8
Release notes

This release contains Mitre Att&ck tagging for the following use cases:

  • User Account Enabled and Disabled within 24 Hours - T1098 - Account Manipulation
  • User Account Removed from the Privileged Group - T1098 - Account Manipulation
  • User Account Brute Force Attempt - T1110 - Brute Force
  • User Account Brute Force Attempt from Multiple Sources - T1110 - Brute Force
  • User Account Brute Force Attempt Reported by Device - T1110 - Brute Force
  • User Account Locked Multiple Times - T1110 - Brute Force
  • User Account Created and Deleted within 24 Hours - T1136 - Create Account
  • User Account Created - T1136 - Create Account
  • User Account Modification - T1098 - Account Manipulation
  • User Account Harvesting Attempt - T1087 - Account Discovery
L1-Entity Monitoring - Indicators and Warnings
29.4 KB
Nov 13, 2018
More info Less info
Product compatibility
Version 6.8 · 6.11.0 · 6.9.1
Version 7.0 · 7.2 · 7.3 · 7.4 · 7.5 · 7.6 · 7.7 · 7.8
Release notes
  • Impossible Travel use cases
L1-Entity Monitoring - Indicators and Warnings
25.1 KB
Jan 24, 2018
More info Less info
Product compatibility
Version 6.8 · 6.11.0 · 6.9.1
Release notes

  This update includes minor bug fixes.  



Unsubscribe from notifications

You are receiving release updates for this item because you have subscribed to the following products:
If you unsubscribe, you will no longer receive any notifications for these products.
Tip: to update your subscription preferences, go to Manage Subscriptions from your Dashboard, uncheck the products you no longer want to receive notifications for, and click 'Save'.

Marketplace Terms of Service

In order to continue, you must accept the updated Marketplace Terms of Service
Since you are downloading an app from the OpenText Marketplace, you need to accept the updated Marketplace Terms of Service before you can continue. Use the link to review the Marketplace Terms of Service. Once complete check the, "I accept the Marketplace Terms of Service" box below and click accept to continue your download.

Your download has begun...

Your download has begun

Related content and resources

Your browser is not supported!

Please upgrade to one of the following broswers: Internet Explorer 11 (or greater) or the latest version of Chrome or Firefox

master-6235 | Wed Sep 18 10:29:05 PDT 2024