Detection of External Remote Services

ID: DET0803
Domains: ICS
Analytics: AN1935
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1935

Monitor for network traffic originating from unknown/unexpected systems.
Monitor authentication logs and analyze for unusual access patterns, windows of activity, and access outside of normal business hours, including use of Valid Accounts.
When authentication is not required to access an exposed remote service, monitor for follow-on activities such as anomalous external use of the exposed API or application.

Log Sources
Data Component Name Channel
Network Traffic Flow (DC0078) Network Traffic None
Logon Session Metadata (DC0088) Logon Session None
Application Log Content (DC0038) Application Log None