Vendor: Ipswitch
June 14, 2023 · View on GitHub
Product: MoveIt DMZ
| Rules | Models | MITRE ATT&CK® TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 119 | 38 | 23 | 9 | 9 |
| Use-Case | Event Types/Parsers | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Abnormal Authentication & Access | account-password-change ↳moveit-account-password-change authentication-failed ↳moveit-authentication-failed ↳moveit-authentication-failed-1 ↳moveit-ssh-login-failed authentication-successful ↳moveit-authentication-successful-1 failed-logon ↳moveit-failed-logon-1 ↳moveit-failed-logon member-added ↳moveit-member-added-2 ↳moveit-member-added-1 | T1078 - Valid Accounts T1110 - Brute Force T1133 - External Remote Services |
|
| Account Manipulation | account-password-change ↳moveit-account-password-change member-added ↳moveit-member-added-2 ↳moveit-member-added-1 | T1098 - Account Manipulation T1136 - Create Account |
|
| Brute Force Attack | failed-logon ↳moveit-failed-logon-1 ↳moveit-failed-logon | T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
| Data Access | file-delete ↳moveit-file-delete-2 ↳moveit-file-delete ↳moveit-file-delete-1 file-write ↳moveit-file-write-2 ↳moveit-file-write-1 | T1083 - File and Directory Discovery |
|
| Data Exfiltration | file-write ↳moveit-file-write-2 ↳moveit-file-write-1 | TA0002 - TA0002 |
|
| Data Leak | file-write ↳moveit-file-write-2 ↳moveit-file-write-1 | T1114.001 - T1114.001 |
|
| Destruction of Data | file-delete ↳moveit-file-delete-2 ↳moveit-file-delete ↳moveit-file-delete-1 | T1070.004 - Indicator Removal on Host: File Deletion T1485 - Data Destruction |
|
| Lateral Movement | authentication-failed ↳moveit-authentication-failed ↳moveit-authentication-failed-1 ↳moveit-ssh-login-failed authentication-successful ↳moveit-authentication-successful-1 failed-logon ↳moveit-failed-logon-1 ↳moveit-failed-logon | T1021.001 - Remote Services: Remote Desktop Protocol T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1110 - Brute Force T1110.003 - T1110.003 T1550.002 - Use Alternate Authentication Material: Pass the Hash T1550.003 - Use Alternate Authentication Material: Pass the Ticket T1558 - Steal or Forge Kerberos Tickets |
|
| Malware | authentication-successful ↳moveit-authentication-successful-1 failed-logon ↳moveit-failed-logon-1 ↳moveit-failed-logon file-write ↳moveit-file-write-2 ↳moveit-file-write-1 | T1003.002 - T1003.002 T1078 - Valid Accounts T1210 - Exploitation of Remote Services T1505.003 - Server Software Component: Web Shell T1547.001 - T1547.001 TA0002 - TA0002 |
|
| Privilege Escalation | failed-logon ↳moveit-failed-logon-1 ↳moveit-failed-logon | T1210 - Exploitation of Remote Services |
|
| Next Page -->> |