Potential Unauthorized Use of ATLAS AI SOC Customizations
Detects when potentially unauthorized or risky customizations to ATLAS AI-driven SOC response workflows are made, which could indicate adversary abuse of automation.
Sigmamediumv12026-07-28
sigmapotential-unauthorized-use-of-atlas-ai-soc-customizations-655e1514
title: Potential Unauthorized Use of ATLAS AI SOC Customizations
id: 3f417f81-48e6-401d-86eb-0accd8bf91c6
description: Detects possible unauthorized or suspicious ATLAS/AI-related customizations or configuration changes in SOC workflows, which may indicate adversary attempts to abuse automation and response capabilities.
logsource:
product: windows
category: application
service: ATLAS
definition: 'ATLAS SIEM/SOC platform logs activity for AI-driven response customization.'
detection:
selection:
EventType|contains: ["Customization", "Automation", "AI"]
UserType|contains: ["API", "External", "Unknown"]
Action|contains: ["Create", "Modify", "Delete"]
condition: selection
level: medium
tags:
- "attack.t1566"
references:
- "https://www.esentire.com/blog/atlas-enhances-its-response-customizations-for-customers-to-leverage-ai-across-all-soc-roles"
falsepositives:
- Legitimate configuration changes by administrators
- Routine customizations by authorized SOC engineers
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.