Vendor: GoAnywhere
June 14, 2023 · View on GitHub
Product: GoAnywhere MFT
| Rules | Models | MITRE ATT&CK® TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 131 | 49 | 22 | 5 | 5 |
| Use-Case | Event Types/Parsers | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Abnormal Authentication & Access | failed-logon ↳goanywhere-failed-logon remote-logon ↳goanywhere-remote-logon-3 ↳goanywhere-remote-logon-2 ↳goanywhere-remote-logon ↳goanywhere-remote-logon-1 | T1021 - Remote Services T1078 - Valid Accounts T1078.002 - T1078.002 T1078.003 - Valid Accounts: Local Accounts T1110 - Brute Force T1133 - External Remote Services |
|
| Brute Force Attack | failed-logon ↳goanywhere-failed-logon | T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
| Data Access | file-delete ↳goanywhere-file-delete ↳goanywhere-file-delete-1 | T1083 - File and Directory Discovery |
|
| Destruction of Data | file-delete ↳goanywhere-file-delete ↳goanywhere-file-delete-1 | T1070.004 - Indicator Removal on Host: File Deletion T1485 - Data Destruction |
|
| Lateral Movement | failed-logon ↳goanywhere-failed-logon remote-logon ↳goanywhere-remote-logon-3 ↳goanywhere-remote-logon-2 ↳goanywhere-remote-logon ↳goanywhere-remote-logon-1 | T1018 - Remote System Discovery T1021 - Remote Services T1021.001 - Remote Services: Remote Desktop Protocol T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1110 - Brute Force T1110.003 - T1110.003 T1550 - Use Alternate Authentication Material T1550.002 - Use Alternate Authentication Material: Pass the Hash T1550.003 - Use Alternate Authentication Material: Pass the Ticket T1558 - Steal or Forge Kerberos Tickets T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting |
|
| Malware | failed-logon ↳goanywhere-failed-logon remote-logon ↳goanywhere-remote-logon-3 ↳goanywhere-remote-logon-2 ↳goanywhere-remote-logon ↳goanywhere-remote-logon-1 | T1078 - Valid Accounts T1210 - Exploitation of Remote Services T1550.003 - Use Alternate Authentication Material: Pass the Ticket T1558 - Steal or Forge Kerberos Tickets TA0002 - TA0002 |
|
| Privilege Escalation | failed-logon ↳goanywhere-failed-logon remote-logon ↳goanywhere-remote-logon-3 ↳goanywhere-remote-logon-2 ↳goanywhere-remote-logon ↳goanywhere-remote-logon-1 | T1078 - Valid Accounts T1210 - Exploitation of Remote Services T1555.005 - T1555.005 |
|
| Ransomware | failed-logon ↳goanywhere-failed-logon remote-logon ↳goanywhere-remote-logon-3 ↳goanywhere-remote-logon-2 ↳goanywhere-remote-logon ↳goanywhere-remote-logon-1 | T1078 - Valid Accounts |
|
| Next Page -->> |