Semperis-DSP-Notifications
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 30001 | DSP critical notification | Operational | N | Y |
Event ID 30001: DSP critical notification
#Description
Semperis DSP raises a notification at Critical severity from its notification-rule engine, which continuously evaluates Active Directory and Entra ID for indicators of exposure or compromise.
Fields #
| Name | Description |
|---|---|
LoginUser | Account extracted from the notification's changedBy field. |
NTDomain | Domain of LoginUser. |
HostName | Host extracted from the notification's Computer field. |
DnsDomain | DNS domain of the host. |
severity | Notification severity; the analytic filters for 'Critical'. |
Community Notes #
Third-party product event (Semperis Directory Services Protector). Consumed by the Semperis-authored Sentinel analytic rule 'Semperis DSP Operations Critical Notifications' (EventSourceName 'Semperis-DSP-Notifications', EventID 30001; mapped to ATT&CK T1133, T1110, T1584). Grounding is vendor documentation.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto # view in coverage
T1110, T1133, T1584