Skip to content

Default Threat Rules

This article provides and overview of the default threat detection rules available to all Hydden customers.

img

Each rule can be specified to be shown in Reports or Posture. By default both options are checked on sll default threat rules.

Default Threat Rules

CategoryNameDescriptionThresholdScore
BreachesAccount Password Not Changed Since Public BreachThis rule flags any accounts that have been identified as having been breached and where the password change date is not known or older than the breach date.-10
Account StatisticsAccount Z-ScoreProvides a mean to identify high absolute z-score values for accounts in groups.-5
Account ActivityAccounts not used in 90+ DaysThis rule flags all accounts that have been stale for 90+ days with a risk score.90+days10
Account ActivityAccounts with 10+ Failed Login Attempts in 1 HourThis rule flags accounts with more than 10 failed login attempts in a period of one hour.10+10
Password and SecurityAccounts with MFA Not EnabledAccounts for which MFA has not been enabled.-8
Owner MappingAccounts with No OwnerAlerts to accounts without owner designation.-8
Password and SecurityAccounts with Password 90+ DaysAccounts with a password age of 90 or more days.90+5
Password and SecurityAccounts with Password Never SetAccounts for which a password was never set up.-10
PrivilegeHighly Privileged Group(s)Groups for which privileges have not been trimmed.-5
PrivilegeHighly Privileged Role(s)Roles for which privileges have not been trimmed.-5
Owner MappingShared AccountAlerts to an account that is shared with another user.-5

Default Aggregation Rules

CategoryNameDescriptionThresholdScore
Total CalculationAccount Activity (Total)internal calculation module-10
Total CalculationAccount Statistics (Total)internal calculation module-10
Total CalculationBreach Data (Total)internal calculation module-10
Total CalculationExpired Accounts (Aggregated)internal calculation module-10
Total CalculationGroup Membership (Total)internal calculation module-10
Total CalculationOwner Mapping (Total)internal calculation module-10
Total CalculationPassword & Security (Total)internal calculation module-10
Total CalculationPrivilege (Total)internal calculation module-10
Total CalculationTotal Threat - the total threat aggregation rule can be configured as Maximum, Totals Average (default), and Weighted Average. Contact Hydden Support to learn more about which setting to use for your specific needs.internal calculation module-100

Hydden Documentation and Training Hub