Vendor: Infoblox

June 14, 2023 · View on GitHub

Product: BloxOne

Use-Case: Privilege Escalation

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
21211
Event TypeRulesModels
remote-logonT1078 - Valid Accounts
AS-PV-UHWoPC: Access to Password Vault managed asset with no password checkout for user
DC18-new: Account switch by new user

T1555.005 - T1555.005
AS-PV-UHWoPC: Access to Password Vault managed asset with no password checkout for user
AS-PV-OA: Password retrieval based accounts