Vendor: Imperva

June 30, 2023 · View on GitHub

Product: Imperva SecureSphere

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
13859877
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessapp-login
cef-securesphere-app-login
cef-securesphere-database-operations

failed-app-login
cef-securesphere-app-login-failed
T1078 - Valid Accounts
T1133 - External Remote Services
  • 15 Rules
  • 4 Models
Compromised Credentialsapp-login
cef-securesphere-app-login
cef-securesphere-database-operations

database-alert
s-securesphere-db-alert
securesphere-db-alert
leef-securesphere-db-alert-1
cef-syslog-securesphere-db-alert
securesphere-db-alert-2
leef-securesphere-db-alert
cef-securesphere-db-alert-1
cef-securesphere-db-alert

database-login
securesphere-db-login-2
cef-securesphere-db-login
cef-syslog-securesphere-db-login
q-leef-securesphere-db-login
s-securesphere-db-login
securesphere-db-login
s-securesphere-db-login-1
cef-securesphere-db-login-1
securesphere-db-json
securesphere-db-cuseqsv

database-query
q-leef-securesphere-db-query
cef-securesphere-db-query-2
s-securesphere-db-query
securesphere-db-query
securesphere-db-query-2
cef-securesphere-db-query
cef-syslog-securesphere-db-query
cef-securesphere-db-query-1
cef-securesphere-database-operations
securesphere-db-json
securesphere-db-cuseqsv

failed-app-login
cef-securesphere-app-login-failed

network-alert
cef-securesphere-db-alert

security-alert
securesphere-alert
securesphere-alert-1
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1078 - Valid Accounts
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
T1213 - Data from Information Repositories
  • 109 Rules
  • 55 Models
Lateral Movementapp-login
cef-securesphere-app-login
cef-securesphere-database-operations

failed-app-login
cef-securesphere-app-login-failed

security-alert
securesphere-alert
securesphere-alert-1
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
  • 6 Rules
Privilege Abuseapp-login
cef-securesphere-app-login
cef-securesphere-database-operations

failed-app-login
cef-securesphere-app-login-failed
T1078 - Valid Accounts
  • 2 Rules
Privileged Activityapp-login
cef-securesphere-app-login
cef-securesphere-database-operations

failed-app-login
cef-securesphere-app-login-failed

security-alert
securesphere-alert
securesphere-alert-1
T1068 - Exploitation for Privilege Escalation
T1078 - Valid Accounts
  • 2 Rules
Ransomwareapp-login
cef-securesphere-app-login
cef-securesphere-database-operations

failed-app-login
cef-securesphere-app-login-failed
T1078 - Valid Accounts
  • 2 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Valid Accounts

Exploitation for Privilege Escalation

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Obfuscated Files or Information

Data from Information Repositories

Proxy: Multi-hop Proxy

Proxy