Vendor: Microsoft

June 14, 2023 · View on GitHub

Product: Windows

Use-Case: Phishing

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
42222
Event TypeRulesModels
process-createdT1566.001 - T1566.001
A-Exec-Outlook-Temp: A suspicious program was executed in the Outlook temp folder on this asset.
Exec-Outlook-Temp: A suspicious program was executed in the Outlook temp folder.
vpn-logoutT1566 - Phishing
EM-FNum-in: Abnormal number of incoming emails
EM-BSum-in: Abnormal size of incoming emails
EM-BSum-in: Sum of bytes in incoming emails
EM-FNum-in: Count of incoming emails