Vendor: Cisco

June 14, 2023 · View on GitHub

Product: ADC

Use-Case: Ransomware

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
10111
Event TypeRulesModels
web-activity-allowedT1071.001 - Application Layer Protocol: Web Protocols
WEB-UI-Ransomware: User attempted to connect to IP address which is associated to Ransomware