Vendor: BeyondTrust

June 14, 2023 · View on GitHub

Product: BeyondInsight

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
117531388
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-creation
beyond-account-add
beyondtrust-account-add

account-deleted
beyond-account-delete

account-switch
beyond-account-retrieve

account-unlocked
beyond-account-unlock

app-activity
beyond-activity-deny
beyond-activity-update
beyondtrust-app-activity-7
beyond-activity-expire
beyondtrust-app-activity-6
beyondtrust-app-activity-8
beyond-activity-cancel
beyond-activity-approve
leef-beyondtrust-app-activity-2
leef-beyondtrust-app-activity-1
leef-beyondtrust-app-activity-6
leef-beyondtrust-app-activity
leef-beyondtrust-app-activity-5
leef-beyondtrust-app-activity-4
cef-beyondtrust-app-activity-1
leef-beyondtrust-app-activity-3
cef-beyondtrust-app-activity-2
leef-beyondtrust-app-activity-9
cef-beyondtrust-app-activity
leef-beyondtrust-app-activity-8
leef-beyondtrust-app-activity-7
leef-beyondtrust-app-activity-10

app-login
leef-beyondtrust-app-login-1
leef-beyondtrust-app-login
cef-beyondtrust-app-login

failed-app-login
leef-beyondtrust-failed-logon
leef-beyondtrust-failed-app-login
leef-beyondtrust-failed-logon-1

privileged-access
beyond-account-retrieve
T1078 - Valid Accounts
T1133 - External Remote Services
  • 15 Rules
  • 4 Models
Account Manipulationaccount-creation
beyond-account-add
beyondtrust-account-add

account-deleted
beyond-account-delete

app-activity
beyond-activity-deny
beyond-activity-update
beyondtrust-app-activity-7
beyond-activity-expire
beyondtrust-app-activity-6
beyondtrust-app-activity-8
beyond-activity-cancel
beyond-activity-approve
leef-beyondtrust-app-activity-2
leef-beyondtrust-app-activity-1
leef-beyondtrust-app-activity-6
leef-beyondtrust-app-activity
leef-beyondtrust-app-activity-5
leef-beyondtrust-app-activity-4
cef-beyondtrust-app-activity-1
leef-beyondtrust-app-activity-3
cef-beyondtrust-app-activity-2
leef-beyondtrust-app-activity-9
cef-beyondtrust-app-activity
leef-beyondtrust-app-activity-8
leef-beyondtrust-app-activity-7
leef-beyondtrust-app-activity-10
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
T1531 - Account Access Removal
  • 24 Rules
  • 9 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

Create Account

External Remote Services

Valid Accounts

Account Manipulation

Create Account: Create: Local Account

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Valid Accounts

Credentials from Password Stores

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy

Account Access Removal