Vendor: Bitdefender

June 14, 2023 · View on GitHub

Product: GravityZone

Use-Case: Privileged Activity

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
40433
Event TypeRulesModels
app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
security-alertT1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
web-activity-deniedT1071.001 - Application Layer Protocol: Web Protocols
A-WEB-DC: Web activity event on a Domain Controller
WEB-ALERT-EXEC: Security violation by Executive in web activity

T1078 - Valid Accounts
WEB-ALERT-EXEC: Security violation by Executive in web activity

T1102 - Web Service
A-WEB-DC: Web activity event on a Domain Controller