
Summary
Detects a newly observed combination of SonicWall firewall login activity that suggests potential credential misuse or unauthorized remote access. The rule triggers when a VPN- or WAN-zone login by a user occurs from a source IP that has not been observed with that user on the same SonicWall appliance in the prior 14 days. It relies on the Elastic SonicWall Firewall integration and logs with event codes 235, 236 (administrator VPN/WAN logins), 237, 238 (remote-user logins), and 1080 (SSL VPN user login). To match, the event must include the appliance serial number (observer.serial_number), a source IP, and a user name. The rule uses a new_terms condition with a 14-day history window to identify genuinely new login-origin pairings, reducing noise from familiar accounts. This mapping aligns with MITRE ATT&CK techniques T1078 (Valid Accounts) and T1133 (External Remote Services) under Initial Access (TA0001). The rule aids threat detection by surfacing anomalous login relationships that merit investigation, triage, and potential containment actions. False positives can occur for new administrators, traveling users, ISP changes, MSP activity, or onboarding events; careful scoping to the appliance, user, and expected source is advised. When suspected, responders should terminate sessions, rotate credentials, verify MFA, and review downstream activity while preserving logs for audit purposes.
Categories
- Network
- Identity Management
Data Sources
- Firewall
ATT&CK Techniques
- T1078
- T1133
Created: 2026-08-21