Vendor: CyberArk

June 14, 2023 · View on GitHub

Product: CyberArk Vault

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
24392341414
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-password-change
cyberark-password-change
cef-cyberark-password-change
s-cyberark-password-change
cef-cyberark-password-change-1

account-password-reset
s-cyberark-password-reset

account-switch
s-cyberark-account-switch-3
s-cyberark-account-switch-2
cyberark-account-switch
cef-cyberark-account-switch-1
cyberark-account-switch-1
cef-cyberark-account-switch
s-cyberark-account-switch

app-activity
s-cyberark-app-activity-9
s-cyberark-app-activity-8
s-cyberark-app-activity-3
s-cyberark-app-activity
s-cyberark-app-activity-2
s-cyberark-app-activity-1
s-cyberark-app-activity-7
s-cyberark-app-activity-6
leef-cyberark-app-activity
s-cyberark-app-activity-5
s-cyberark-app-activity-4
s-cyberark-activity-6
s-cyberark-activity-7
cef-cyberark-app-activity

app-login
cef-cyberark-app-login
cyberark-app-login
s-cyberark-app-login

failed-app-login
cef-cyberark-failed-app-login
s-cyberark-app-login

failed-logon
s-cyberark-failed-logon
s-cyberark-failed-logon-1

remote-logon
s-cyberark-remote-logon-1
s-cyberark-activity-4
s-cyberark-remote-logon-2
s-cyberark-activity-5
s-cyberark-activity
s-cyberark-activity-1
T1021 - Remote Services
T1078 - Valid Accounts
T1078.002 - T1078.002
T1078.003 - Valid Accounts: Local Accounts
T1110 - Brute Force
T1133 - External Remote Services
  • 40 Rules
  • 16 Models
Account Manipulationaccount-password-change
cyberark-password-change
cef-cyberark-password-change
s-cyberark-password-change
cef-cyberark-password-change-1

account-password-reset
s-cyberark-password-reset

app-activity
s-cyberark-app-activity-9
s-cyberark-app-activity-8
s-cyberark-app-activity-3
s-cyberark-app-activity
s-cyberark-app-activity-2
s-cyberark-app-activity-1
s-cyberark-app-activity-7
s-cyberark-app-activity-6
leef-cyberark-app-activity
s-cyberark-app-activity-5
s-cyberark-app-activity-4
s-cyberark-activity-6
s-cyberark-activity-7
cef-cyberark-app-activity
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 4 Rules
  • 1 Models
Brute Force Attackfailed-logon
s-cyberark-failed-logon
s-cyberark-failed-logon-1
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules
Data Exfiltrationfile-write
s-cyberark-file-write-1
s-cyberark-file-write-2
s-cyberark-app-activity
leef-cyberark-app-activity
cef-cyberark-app-activity
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Destruction of Datafile-delete
s-cyberark-file-delete
s-cyberark-app-activity
leef-cyberark-app-activity
cef-cyberark-app-activity
T1070.004 - Indicator Removal on Host: File Deletion
T1485 - Data Destruction
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Server Software Component: Web Shell

Account Manipulation

Server Software Component

Boot or Logon Autostart Execution

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Exploitation for Privilege Escalation

Boot or Logon Autostart Execution

Obfuscated Files or Information: Indicator Removal from Tools

Indicator Removal on Host: File Deletion

Valid Accounts

Use Alternate Authentication Material

Use Alternate Authentication Material: Pass the Hash

Indicator Removal on Host

Use Alternate Authentication Material: Pass the Ticket

Obfuscated Files or Information

Valid Accounts: Local Accounts

OS Credential Dumping

Brute Force

Steal or Forge Kerberos Tickets

Credentials from Password Stores

Steal or Forge Kerberos Tickets: Kerberoasting

File and Directory Discovery

Remote System Discovery

Exploitation of Remote Services

Remote Services

Use Alternate Authentication Material

Remote Services: Remote Desktop Protocol

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy

Data Destruction

Data Encrypted for Impact