Vendor: CyberArk

June 14, 2023 · View on GitHub

Product: Endpoint Privilege Management

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
5324633
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessprivileged-access
cyberark-privileged-access

privileged-object-access
json-cyberark-privileged-object-access
T1078 - Valid Accounts
  • 1 Rules
  • 1 Models
Compromised Credentialsprocess-alert
cyberark-process-alert
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
TA0002 - TA0002
  • 7 Rules
  • 2 Models
Malwareprivileged-access
cyberark-privileged-access

privileged-object-access
json-cyberark-privileged-object-access

process-alert
cyberark-process-alert
T1053.003 - T1053.003
T1190 - Exploit Public Fasing Application
T1562.004 - Impair Defenses: Disable or Modify System Firewall
TA0002 - TA0002
  • 32 Rules
  • 10 Models
Privilege Abuseprivileged-access
cyberark-privileged-access
T1078 - Valid Accounts
  • 5 Rules
  • 5 Models
Privileged Activityprivileged-access
cyberark-privileged-access
TA0002 - TA0002
  • 10 Rules
  • 7 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Exploit Public Fasing Application

Scheduled Task/Job

Valid Accounts

Scheduled Task/Job

Valid Accounts

Scheduled Task/Job

Impair Defenses

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Impair Defenses: Disable or Modify System Firewall

Obfuscated Files or Information