↳ GitHub sourceAnalytics ruleMedium

Acronis - Multiple Endpoints Accessing Malicious URLs

Description

Multiple endpoints accessing malicious URLs could indicate an ongoing phishing attack, with several employees interacting with those URLs.
Rule type
Scheduled
Version
1.0.0
Query frequency
1h
Query period
1d
Trigger
gt 2

Declared MITRE coverage

KQL query

Original query, unchanged.

CommonSecurityLog
| where DeviceVendor == "Acronis"
| where DeviceEventClassID == "MaliciousUrlDetected"
| summarize MaliciousUrlDetected = count() by DeviceName

Declared entities

Host

Related content

Links established from declared identifiers and solution manifests.

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
1385f0ce-69d9-4abf-8039-52080c8c7017
Additional source files 2Solutions/Acronis Cyber Protect Cloud/Analytic Rules/AcronisMultipleEndpointsAccessingMaliciousURLs.yamlsource ↗Solutions/Acronis Cyber Protect Cloud/Data/Solution_AcronisCyberProtectCloud.jsonsolution-membership ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 05:49 UTC

GSTEP sync dates, separate from the source content’s publication dates.