Vendor: CrowdStrike

June 14, 2023 · View on GitHub

Product: Falcon

Use-Case: Privileged Activity

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
26871515
Event TypeRulesModels
app-activityT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
APP-AT-PRIV: Non-privileged user performing privileged application activity
APP-AT-PRIV: Privileged application activities
app-activity-failedT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
failed-app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
file-alertT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-deleteT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-downloadT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-readT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-writeT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
local-logonT1078 - Valid Accounts
AL-F-F-CS: First logon to a critical system for user
AL-F-A-CS: Abnormal logon to a critical system for user
AL-UH-CS-NC: Logon to a critical system for a user with no information
AL-OU-F-CS: First logon to a critical system that user has not previously accessed
AL-HT-PRIV: Non-Privileged logon to privileged asset
AL-HT-EXEC-new: New user logon to executive asset

T1078.002 - T1078.002
AL-F-F-DC-G: First logon to a Domain Controller for peer group
AL-F-A-DC-G: Abnormal logon to a Domain Controller for Peer Group
AL-UH-F-DC: First logon to this Domain Controller for user
AL-UH-A-DC: Abnormal logon to a Domain Controller that user has not accessed often previously
AL-UH-DC-NC: Logon to a Domain Controller for user with no information
AL-HT-EXEC: Executive Assets
AL-HT-PRIV: Privilege Users Assets
RA-UH: Assets accessed by this user remotely
AL-UH-DC: Logons to Domain Controllers
AL-OU-CS: Logon to critical servers
process-createdT1482 - Domain Trust Discovery
A-Trickbot-Recon: Trickbot malware domain recon activity on this asset
Trickbot-Recon: Trickbot malware domain recon activity
remote-accessT1021 - Remote Services
RA-UH-CS-NC: Remote access to a critical system for user with no information
RA-F-F-CS: First remote access to critical system for user
RA-F-A-CS: Abnormal remote access to critical system for user
RA-HT-EXEC-new: New user remote access to executive asset

T1078 - Valid Accounts
RA-UH-CS-NC: Remote access to a critical system for user with no information
RA-F-F-CS: First remote access to critical system for user
RA-F-A-CS: Abnormal remote access to critical system for user
RA-HT-EXEC-new: New user remote access to executive asset

T1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
AL-HT-EXEC: Executive Assets
RA-UH: Assets accessed by this user remotely
remote-logonT1078 - Valid Accounts
AL-F-F-CS: First logon to a critical system for user
AL-F-A-CS: Abnormal logon to a critical system for user
AL-UH-CS-NC: Logon to a critical system for a user with no information
AL-OU-F-CS: First logon to a critical system that user has not previously accessed
AL-HT-PRIV: Non-Privileged logon to privileged asset
AL-HT-EXEC-new: New user logon to executive asset

T1021 - Remote Services
RL-UZ-F-DC: First logon to a Domain Controller from zone for user
RL-OZ-F-DC: First logon to a Domain Controller from zone for organization
RL-OZ-A-DC: Abnormal logon to a Domain Controller from zone for organization

T1078.002 - T1078.002
AL-F-F-DC-G: First logon to a Domain Controller for peer group
AL-F-A-DC-G: Abnormal logon to a Domain Controller for Peer Group
AL-UH-F-DC: First logon to this Domain Controller for user
AL-UH-A-DC: Abnormal logon to a Domain Controller that user has not accessed often previously
AL-UH-DC-NC: Logon to a Domain Controller for user with no information
RL-UZ-F-DC: First logon to a Domain Controller from zone for user
RL-OZ-F-DC: First logon to a Domain Controller from zone for organization
RL-OZ-A-DC: Abnormal logon to a Domain Controller from zone for organization

T1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
AL-HT-EXEC: Executive Assets
AL-HT-PRIV: Privilege Users Assets
RL-OZ-DC: Source zones in the organization during domain controller access
RL-UZ-DC: Source zones per user logging into domain controller
RA-UH: Assets accessed by this user remotely
AL-UH-DC: Logons to Domain Controllers
AL-OU-CS: Logon to critical servers
security-alertT1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
task-createdT1053.005 - Scheduled Task/Job: Scheduled Task
WTC-HT-EXEC: Non-Executive user created a scheduled task/service on executive asset
WTC-HT-PRIV: Non-Privileged user created a scheduled task/service on privileged asset

T1543.003 - Create or Modify System Process: Windows Service
WTC-HT-EXEC: Non-Executive user created a scheduled task/service on executive asset
WTC-HT-PRIV: Non-Privileged user created a scheduled task/service on privileged asset
AL-HT-PRIV: Privilege Users Assets
AL-HT-EXEC: Executive Assets