Vendor: Microsoft

June 14, 2023 · View on GitHub

Product: AppLocker

Use-Case: Lateral Movement

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
40111
Event TypeRulesModels
security-alertT1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
A-ALERT-DL: DL Correlation rule alert on asset
A-ALERT-Correlation-Rule: Correlation rule alert on asset
ALERT-Correlation-Rule: Correlation rule alert on asset accessed by this user
ALERT-DL: DL Correlation rule alert on asset accessed by this user