Vendor: Cisco

June 14, 2023 · View on GitHub

Product: Cisco Secure Email

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
3917344
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Data Leakdlp-email-alert-out
cisco-esa-dlp-alert-2

dlp-email-alert-out-failed
cisco-esa-dlp-alert-2
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 34 Rules
  • 16 Models
Malwaredlp-email-alert-in
cisco-esa-dlp-alert-2

dlp-email-alert-out
cisco-esa-dlp-alert-2
T1190 - Exploit Public Fasing Application
  • 1 Rules
Phishingdlp-email-alert-out
cisco-esa-dlp-alert-2
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 1 Rules
  • 1 Models
Privilege Abusedlp-email-alert-in
cisco-esa-dlp-alert-2

dlp-email-alert-in-failed
cisco-esa-dlp-alert-2

dlp-email-alert-out
cisco-esa-dlp-alert-2

dlp-email-alert-out-failed
cisco-esa-dlp-alert-2
T1078 - Valid Accounts
  • 1 Rules
Privileged Activitydlp-email-alert-in
cisco-esa-dlp-alert-2

dlp-email-alert-in-failed
cisco-esa-dlp-alert-2

dlp-email-alert-out
cisco-esa-dlp-alert-2

dlp-email-alert-out-failed
cisco-esa-dlp-alert-2
T1078 - Valid Accounts
  • 1 Rules
Workforce Protectiondlp-email-alert-out
cisco-esa-dlp-alert-2
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 4 Rules
  • 1 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Exploit Public Fasing Application

Valid Accounts

Valid Accounts

Valid Accounts

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol