Vendor: Microsoft

November 7, 2023 · View on GitHub

Product: SQL Server

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
4115455
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessauthentication-failed
microsoft-mssql-authentication-attempt

authentication-successful
microsoft-mssql-authentication-attempt

failed-app-login
s-failed-app-login
exalms-sqlserver-failed-login
exalms-sqlserver-failed-login-1
T1078 - Valid Accounts
T1133 - External Remote Services
  • 14 Rules
  • 4 Models
Compromised Credentialsauthentication-successful
microsoft-mssql-authentication-attempt

database-login
leef-mssql-database-login-1
leef-mssql-database-login-2
s-database-login-18454
s-database-login-18453
cef-syslog-microsoft-db-login
cef-syslog-microsoft-db-impersonate
s-mssql-database-login-xml
s-mssql-database-login
mssql-database-login
cef-microsoft-database-login
s-mssql-database-login-1
xml-mssql-database-login
xml-mssql-database-login-1
cef-mssql-database-login
s-microsoft-database-login

database-query
s-mssql-database-query-sl-1
xml-mssql-database-login
mssql-database-query-3
s-mssql-database-query-sl-xml
s-mssql-database-query-al
s-mssql-database-query-dl
s-mssql-database-query-sl
s-mssql-database-query-dl-xml
s-mssql-database-query-al-xml
mssql-database-query-2

failed-app-login
s-failed-app-login
exalms-sqlserver-failed-login
exalms-sqlserver-failed-login-1
T1078 - Valid Accounts
T1133 - External Remote Services
T1213 - Data from Information Repositories
  • 26 Rules
  • 14 Models
Lateral Movementauthentication-failed
microsoft-mssql-authentication-attempt

authentication-successful
microsoft-mssql-authentication-attempt

failed-app-login
s-failed-app-login
exalms-sqlserver-failed-login
exalms-sqlserver-failed-login-1
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
  • 1 Rules
Malwareauthentication-successful
microsoft-mssql-authentication-attempt
T1078 - Valid Accounts
  • 1 Rules
Privilege Abusefailed-app-login
s-failed-app-login
exalms-sqlserver-failed-login
exalms-sqlserver-failed-login-1
T1078 - Valid Accounts
  • 1 Rules
Privileged Activityfailed-app-login
s-failed-app-login
exalms-sqlserver-failed-login
exalms-sqlserver-failed-login-1
T1078 - Valid Accounts
  • 1 Rules
Ransomwareauthentication-failed
microsoft-mssql-authentication-attempt

authentication-successful
microsoft-mssql-authentication-attempt

failed-app-login
s-failed-app-login
exalms-sqlserver-failed-login
exalms-sqlserver-failed-login-1
T1078 - Valid Accounts
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

External Remote Services

Valid Accounts

Valid Accounts

Valid Accounts

Data from Information Repositories

Proxy: Multi-hop Proxy

Proxy