Hi;
For the Threshold based detector which detects 5 failed login attempts to a corporate O365 account in 1 minute, is this relying on gatelets or can it be done using securelets.
I think it is gatelets. However, thought I'd ask anyway.
Kindly
Wasfi
It is for Securlet and Gatelet, please see here: https://techdocs.broadcom.com/us/en/symantec-security-software/information-security/symantec-cloudsoc/cloud/detect-home/understanding-detectors/threshold-based-incident-detectors.html
However, please note that the Securlet events can be delayed whereas Gatelet would be near instant.