Default Rules

This article provides and overview of the default threat detection rules available to all Hydden customers.

img
Hydden's threat rules page

The rules are grouped into categories and names:

CategoryNameDescriptionThresholdScore
Account ActivityMore than {x} Failed Login AttemptsHydden has rules configured for 5, 10, 20, and 25 failed login attempts. These are configured with the entity set to Account.5 attempts6
10 attempts7
20 attempts8
25 attempts9
Account ActivityStale Account {x}+ DaysHydden has rules configured for 90+, 180+, 275+, and 360+ days for stale accounts. These are configured with the entity set to Account.90+days2
180+ days3
275+ days4
365+ days5
Account StatisticsAccount Z-ScoreProvides a mean to identify high absolute z-score values for accounts in groups.-10
BreachesBreached Account(s)These are configured with the entity set to Account.-5
BreachesBreached Account(s) High RiskThese are configured with the entity set to Account.-5
Group MembershipGroup(s) 500+Large group detection, configured with an entity of Group Membership.500+ groups2
Identity MappingNo OwnerAlerts to accounts without owner designation. Configured with an entity of Account.-7
Identity MappingShared AccountAlerts to an account that is shared with another user. Configured with an entity of Account.-8
Identity MappingShared Account+Alerts to an account that is shared with more than one other user. Configured with an entity of Account.1+10
Password and SecurityMFA Not EnabledAccounts for which MFA has not been enabled.-6
Password and SecurityMFA Status N/AAccounts for which an MFA status is not available.-2
Password and SecurityPassword 180+ DaysAccounts with a password age of 180 or more days.180+4
Password and SecurityPassword 90+ DaysAccounts with a password age of 90 or more days.90+8
Password and SecurityPassword Never SetAccounts for which a password was never set up.-2
PrivilegeHigh Privileged Group(s)Groups for which privileges have not been trimmed.-4
PrivilegeHigh Privileged Role(s)Roles for which privileges have not been trimmed.-4
PrivilegePrivileged Group(s)Groups with privileges.-2
Total CalculationAccount Activity (Total)internal calculation module-6
Total CalculationBreach Data (Total)internal calculation module-10
Total CalculationExpired Accounts (Aggregated)internal calculation module-10
Total CalculationGroup Membership (Total)internal calculation module-0
Total CalculationIdentity Mapping (Total)internal calculation module-0
Total CalculationPassword & Security (Total)internal calculation module-8
Total CalculationPrivilege (Total)internal calculation module-10
Total CalculationTotal Threat (Max)internal calculation module-100
Total CalculationTotal Threat (Weighted Avg)internal calculation module-100