Skip to main content

INTERCEPT Offenses in QRadar

The Netwrix Active Directory App for QRadar feeds several QRadar Offenses.

INTERCEPT Offenses in QRadar

While the Authentication Attacks Dashboard reports on incidents monitored by Threat Prevention Authentication Analytics, these incidents also generate offenses.

QRadar OffenseThreat Prevention Analytic Definition
INTERCEPT: Bad User ID (By Source Host)Pre-authentication failures using one or more non-existing user IDs
INTERCEPT: Bad User ID (By User)Pre-authentication failures using one or more non-existing user IDs
INTERCEPT: Breached PasswordMultiple failed authentications followed by a successful authentication
INTERCEPT: Brute Force AttacksRepeated failed authentications against systems and other network assets in a specified time range
INTERCEPT: Concurrent LoginsLogins from multiple locations simultaneously
INTERCEPT: File System Attacks (By User)Significant number of file changes made by an account in a short time period
INTERCEPT: Golden TicketsKerberos tickets with modified maximum lifetimes for a user ticket and maximum lifetimes for a user ticket renewal
INTERCEPT: Horizontal Account MovementUser account authentications across multiple network assets in a specified time period
INTERCEPT: Impersonation LoginsMultiple authenticated accounts from a single system
INTERCEPT: User Account HackingRepeated failed logins below lockout thresholds and/or over extended periods

Additional offenses may be generated by the Netwrix Active Directory App.

QRadar OffenseDefinition
INTERCEPT: Domain Admin ActivityWhen a Domain Admin makes at least X Active Directory modifications within the defined time frame
INTERCEPT: First-Time/Stale Client Host UseWhen a user authenticates from a host for the first time or when a user account that has become stale authenticates from a host
INTERCEPT (Sense): First-Time/Stale Client Host UseSends INTERCEPT: Honey Accounts offenses to IBM QRadar User Behavior Analytics App
INTERCEPT: Honey AccountsWhen any activity occurs on a specified Honey Account
INTERCEPT (Sense): Honey AccountsSends INTERCEPT: Honey Accounts offenses to IBM QRadar User Behavior Analytics App
INTERCEPT: OU MovedWhen an OU is moved within Active Directory
INTERCEPT: Password ChangesWhen a single perpetrator makes more than X password changes within the specified timeframe
INTERCEPT: Privilege EscalationWhen group members are added to any of the following built-in privileged groups: Enterprise Admins, Schema Admins, Domain Admins, Administrator, Backup Operator, Account Operators, and Print Operators
INTERCEPT (Sense): Privilege EscalationSends INTERCEPT: Privilege Escalation offenses to IBM QRadar User Behavior Analytics App
INTERCEPT: Sensitive Group ModificationsWhen X occurrences of a group membership change happen to a sensitive group
INTERCEPT: SID History TamperingWhen activity results in the modification of SID history
INTERCEPT (Sense): SID History TamperingSends INTERCEPT: SID History Tampering offenses to IBM QRadar User Behavior Analytics App
INTERCEPT: Stale User Account ActivityWhen events are generated by a user account that has become stale
INTERCEPT (Sense): Stale User Account ActivitySends INTERCEPT: Stale User Account Activity offenses to IBM QRadar User Behavior Analytics App
INTERCEPT: SYSVOL TamperingWhen X occurrences happen for file changes under SYSVOL within the defined timeframe
INTERCEPT: User LockoutsWhen X occurrences happen within the defined timeframe where a user is getting locked out