Semperis-DSP-Notifications

EventTitleChannelSampleRule
30001DSP critical notificationOperationalNY

Event ID 30001: DSP critical notification

#
Channel
Operational

Description

Semperis DSP raises a notification at Critical severity from its notification-rule engine, which continuously evaluates Active Directory and Entra ID for indicators of exposure or compromise.

Fields #

NameDescription
LoginUserAccount extracted from the notification's changedBy field.
NTDomainDomain of LoginUser.
HostNameHost extracted from the notification's Computer field.
DnsDomainDNS domain of the host.
severityNotification severity; the analytic filters for 'Critical'.

Community Notes #

Third-party product event (Semperis Directory Services Protector). Consumed by the Semperis-authored Sentinel analytic rule 'Semperis DSP Operations Critical Notifications' (EventSourceName 'Semperis-DSP-Notifications', EventID 30001; mapped to ATT&CK T1133, T1110, T1584). Grounding is vendor documentation.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

References #