Filecatalyst Detection And Response ((exclusive)) ❲8K 2025❳

| Use Case | Query Logic | Severity | |----------|-------------|----------| | | event_type="login_failure" | stats count by src_ip > 5 in 1 min | High | | Anonymous transfer | user="anonymous" AND bytes_transferred > 10485760 | Critical | | Off-hours exfiltration | time between 22:00-06:00 AND direction="outbound" AND user!=service_account | Medium | | Deleted audit trail | log_message contains "audit log cleared" OR "transfer.log truncated" | Critical |

A dedicated detection and response framework for FileCatalyst addresses three primary risks: filecatalyst detection and response

The foundation of detection is visibility. FileCatalyst Server and Central provide extensive logs, but these must be ingested into a system. | Use Case | Query Logic | Severity