Vendor: McAfee

June 14, 2023 · View on GitHub

Product: MDAM

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
4222222
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Compromised Credentialsdatabase-alert
cef-mdam-db-alert-1
cef-mdam-db-alert

database-query
s-mdam-db-query
T1213 - Data from Information Repositories
  • 38 Rules
  • 20 Models
Data Accessdatabase-alert
cef-mdam-db-alert-1
cef-mdam-db-alert

database-query
s-mdam-db-query
T1213 - Data from Information Repositories
  • 38 Rules
  • 20 Models
Data Exfiltrationdatabase-alert
cef-mdam-db-alert-1
cef-mdam-db-alert
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Malwaredatabase-alert
cef-mdam-db-alert-1
cef-mdam-db-alert
TA0002 - TA0002
  • 2 Rules
  • 1 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Data from Information Repositories