Vendor: IBM

June 14, 2023 · View on GitHub

Product: Infosphere Guardium

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
4222233
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Compromised Credentialsdatabase-alert
cef-guardium-db-alert-1
s-guardium-db-alert
s-guardium-db-alert-1
cef-syslog-guardium-db-alert
cef-syslog-guardium-db-alert-1
cef-guardium-db-alert
cef-guardium-database-alert

database-login
s-db-login

database-query
cef-guardium-db-query
cef-syslog-guardium-db-query
guardium-db-query
leef-guardium-db-query
leef-guardium-db-query-1
T1213 - Data from Information Repositories
  • 38 Rules
  • 20 Models
Data Accessdatabase-alert
cef-guardium-db-alert-1
s-guardium-db-alert
s-guardium-db-alert-1
cef-syslog-guardium-db-alert
cef-syslog-guardium-db-alert-1
cef-guardium-db-alert
cef-guardium-database-alert

database-login
s-db-login

database-query
cef-guardium-db-query
cef-syslog-guardium-db-query
guardium-db-query
leef-guardium-db-query
leef-guardium-db-query-1
T1213 - Data from Information Repositories
  • 38 Rules
  • 20 Models
Data Exfiltrationdatabase-alert
cef-guardium-db-alert-1
s-guardium-db-alert
s-guardium-db-alert-1
cef-syslog-guardium-db-alert
cef-syslog-guardium-db-alert-1
cef-guardium-db-alert
cef-guardium-database-alert
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Malwaredatabase-alert
cef-guardium-db-alert-1
s-guardium-db-alert
s-guardium-db-alert-1
cef-syslog-guardium-db-alert
cef-syslog-guardium-db-alert-1
cef-guardium-db-alert
cef-guardium-database-alert
TA0002 - TA0002
  • 2 Rules
  • 1 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Data from Information Repositories