Vendor: Cisco
June 14, 2023 · View on GitHub
Product: Firepower
Use-Case: Data Access
| Rules | Models | MITRE ATT&CK® TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 3 | 1 | 2 | 2 | 2 |
| Event Type | Rules | Models |
|---|---|---|
| process-created | T1003 - OS Credential Dumping ↳ A-CP-Sensitive-Files: Copying sensitive files with credential data on this asset ↳ CP-Sensitive-Files: Copying sensitive files with credential data | |
| vpn-logout | T1110 - Brute Force ↳ APP-UFL-COUNT: Abnormal number of failed application logins for user | • APP-UFL-COUNT: Count of failed application logins in a session |