Vendor: Microsoft

June 14, 2023 · View on GitHub

Product: DirectAccess

Use-Case: Privilege Abuse

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
10211
Event TypeRulesModels
vpn-loginT1078 - Valid Accounts
SL-UA-F-VPN: First VPN connection for service account

T1133 - External Remote Services
SL-UA-F-VPN: First VPN connection for service account