@@ -2850,7 +2850,7 @@ Synapse.SQLPool_ShellExternalSourceAnomaly)
2850
2850
2851
2851
** [ MITRE tactics] ( #mitre-attck-tactics ) ** : Execution
2852
2852
2853
- ** Severity** : High
2853
+ ** Severity** : High/Medium
2854
2854
2855
2855
### ** Unusual payload with obfuscated parts has been initiated by SQL Server**
2856
2856
@@ -2860,7 +2860,7 @@ Synapse.SQLPool_ShellExternalSourceAnomaly)
2860
2860
2861
2861
** [ MITRE tactics] ( #mitre-attck-tactics ) ** : Execution
2862
2862
2863
- ** Severity** : High
2863
+ ** Severity** : High/Medium
2864
2864
2865
2865
## Alerts for open-source relational databases
2866
2866
@@ -2876,7 +2876,7 @@ SQL.MySQL_BruteForce)
2876
2876
2877
2877
** [ MITRE tactics] ( #mitre-attck-tactics ) ** : PreAttack
2878
2878
2879
- ** Severity** : High
2879
+ ** Severity** : Medium
2880
2880
2881
2881
### ** Suspected successful brute force attack**
2882
2882
@@ -2900,7 +2900,7 @@ SQL.MariaDB_BruteForce)
2900
2900
2901
2901
** [ MITRE tactics] ( #mitre-attck-tactics ) ** : PreAttack
2902
2902
2903
- ** Severity** : High
2903
+ ** Severity** : Medium
2904
2904
2905
2905
### ** Attempted logon by a potentially harmful application**
2906
2906
@@ -2912,7 +2912,7 @@ SQL.MySQL_HarmfulApplication)
2912
2912
2913
2913
** [ MITRE tactics] ( #mitre-attck-tactics ) ** : PreAttack
2914
2914
2915
- ** Severity** : High
2915
+ ** Severity** : High/Medium
2916
2916
2917
2917
### ** Login from a principal user not seen in 60 days**
2918
2918
@@ -2924,7 +2924,7 @@ SQL.MySQL_PrincipalAnomaly)
2924
2924
2925
2925
** [ MITRE tactics] ( #mitre-attck-tactics ) ** : Exploitation
2926
2926
2927
- ** Severity** : Medium
2927
+ ** Severity** : Low
2928
2928
2929
2929
### ** Login from a domain not seen in 60 days**
2930
2930
0 commit comments