Vendor: Microsoft

August 30, 2023 · View on GitHub

Product: Azure Security Center

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
145661255
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Compromised Credentialsdatabase-alert
cef-security-graph-alert-1
cef-security-graph-alert-2
cef-security-graph-alert

network-alert
azure-security-center-network-alert

process-alert
azure-security-center-process-alert
cef-microsoft-process-alert-1
cef-microsoft-process-alert

security-alert
azure-security-alert-2
azure-security-center-security-alert-2
azure-security-center-security-alert-1
cef-azure-security-alert
azure-security-center-security-alert-12
azure-security-center-security-alert
azure-security-center-security-alert-10
azure-security-center-security-alert-11
q-microsoft-asc-security-alert
azure-security-center-security-alert-4
azure-security-center-security-alert-3
azure-security-center-security-alert-6
azure-security-center-security-alert-5
azure-security-center-security-alert-8
azure-security-center-security-alert-7
azure-security-center-security-alert-9
q-microsoft-asc-security-alert-4
q-microsoft-asc-security-alert-3
q-microsoft-asc-security-alert-2
q-microsoft-asc-security-alert-1
cef-microsoft-security-alert-1
cef-microsoft-security-alert
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1078 - Valid Accounts
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
T1213 - Data from Information Repositories
TA0002 - TA0002
  • 79 Rules
  • 38 Models
Data Accessdatabase-alert
cef-security-graph-alert-1
cef-security-graph-alert-2
cef-security-graph-alert
T1213 - Data from Information Repositories
  • 32 Rules
  • 17 Models
Data Exfiltrationdatabase-alert
cef-security-graph-alert-1
cef-security-graph-alert-2
cef-security-graph-alert

dlp-alert
cef-microsoft-dlp-alert
T1020 - Automated Exfiltration
T1071 - Application Layer Protocol
TA0002 - TA0002
TA0010 - TA0010
  • 31 Rules
  • 19 Models
Data Leakdlp-alert
cef-microsoft-dlp-alert
T1020 - Automated Exfiltration
T1071 - Application Layer Protocol
TA0010 - TA0010
  • 29 Rules
  • 18 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

Scheduled Task/Job

External Remote Services

Valid Accounts

Scheduled Task/Job

Valid Accounts

Exploitation for Privilege Escalation

Scheduled Task/Job

Impair Defenses

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Impair Defenses: Disable or Modify System Firewall

Obfuscated Files or Information

Data from Information Repositories

Application Layer Protocol

Automated Exfiltration