Vendor: Microsoft

August 30, 2023 · View on GitHub

Product: Windows

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
10522831505050
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-creation
syslog-json-4720
cef-4720
cef-windows-account-4720
sk4-json-4720
s-xml-4720
raw-windows-account-624
wls-4720
s-4720-jp
mcafee-siem-4720
windows-xml-4720
raw-windows-account-4720
cef-624
ad-json-4720
json-4720-1
json-4720
l-4720
ad-audit-4720

account-deleted
s-xml-4726
raw-windows-account-4726
json-4726
s-4726-jp
nxlog-json-4726
wls-4726
mcafee-siem-4726
raw-windows-account-630
ad-audit-4726
raw-4743
raw-4743-1
ad-audit-4743
raw-4743-2

account-disabled
s-xml-4725
raw-windows-account-629
syslog-json-4725
cef-4725
wls-4725
sk4-json-4725
n-forwarded-cef-4725
mcafee-siem-4725
raw-windows-account-4725
json-4725
s-4725-jp
l-4725
s-windows-event-4725
s-windows-event-629
ad-audit-4725

account-enabled
syslog-json-4722
cef-4722
sk4-json-4722
mcafee-siem-4722
n-forwarded-cef-4722
json-4722
raw-windows-account-4722
windows-xml-4722
ad-json-4722
l-4722
s-windows-event-626
s-windows-event-4722
s-4722-jp
ad-audit-4722

account-lockout
cef-4740
s-4740-2
s-windows-event-644
s-4740-1
raw-windows-account-644
raw-windows-account-4740
n-forwarded-cef-4740
s-windows-event-4740
wls-4740
mcafee-siem-4740
s-xml-4740
json-4740-1
json-4740
ad-json-4740
l-4740
wls-644
emc-syslog-4740
q-microsoft-4740
s-4740-jp
syslog-json-4740
ad-audit-4740
cef-ad-fs-audit-516
s-516

account-password-change
s-xml-4723
syslog-json-4723
cef-4723
s-627
raw-4723
mcafee-siem-4723
wls-4723
json-4723
nic-627
emc-syslog-4723
wls-627
l-4723
raw-627
s-4723-jp
s-windows-event-4723
s-windows-event-627
json-4723-1
json-4723-2
ad-audit-4723

account-password-reset
s-xml-4724
syslog-json-4724
cef-4724
ad-json-4724
wls-4724
sk4-json-4724
mcafee-siem-4724
q-628
n-forwarded-cef-4724
raw-4724
json-4724
raw-628
s-windows-event-4724
l-4724
s-4724-jp
json-4724-1
json-4724-2
ad-audit-4724

account-switch
raw-552
s-windows-event-552
q-microsoft-4648
json-4648-1
n-forwarded-cef-4648
n-forwarded-cef-552
xml-4648
json-4648
json-4648-2
emc-syslog-4648
s-windows-event-4648
s-4648-jp
exalms-552
raw-4648-2
syslog-4648
cef-4648
raw-4648-3
s-windows-4648
raw-4648-4
cef-snare-552
raw-4648-5
mcafee-siem-4648
raw-4648
cef-snare-4648
raw-4648-1
windows-events-4648

account-unlocked
json-4767
syslog-json-4767
l-4767
xml-4767
ad-json-4767
sk4-json-4767
wazuh-4767
raw-4767
ad-audit-4767

app-login
wazuh-sql-login
azure-app-logon
azure-app-logon-2
azure-app-logon-3

audit-log-clear
cef-1102
raw-1102
s-xml-1102
s-517
xml-1102
xml-104
snare-517
s-1102
xml-1102-1
q-1102
s-windows-event-1102
snare-1102
raw-104

audit-policy-change
s-4719-1
q-microsoft-4719
cef-snare-4719
xml-4719
s-612
s-windows-event-4719
raw-4719
snare-4719
json-4719
s-4719
snare-612
exalms-4719

authentication-failed
q-adfs-auth-failed-2
q-adfs-auth-failed
q-adfs-auth-failed-1
adfs-auth-failed
s-adfs-auth-failed
cef-ad-fs-audit-299
cef-ad-fs-audit-501
cef-ad-fs-audit-500
cef-ad-fs-audit-411
cef-ad-fs-audit-413
cef-azure-authentication
azure-app-auth-events
json-windows-auth
s-xml-1203
s-xml-1203-1
s-xml-1201-1

authentication-successful
adfs-500-auth-successful
q-adfs-auth-successful-1
q-adfs-auth-successful
adfs-299-auth-successful
cef-ad-fs-audit-299
cef-ad-fs-audit-501
cef-ad-fs-audit-500
adfs-501-auth-successful
cef-azure-authentication
azure-app-auth-events
json-windows-auth
s-xml-1202
s-xml-1200
s-xml-1200-1
s-xml-1202-1

failed-app-login
wazuh-sql-login
azure-app-logon
azure-app-logon-2
azure-app-logon-3

failed-logon
cef-4776
raw-4776
json-4768-3
cef-snare-680
raw-4771
wazuh-4776
xml-4768
s-windows-4776
cef-4771
s-windows-4771
xml-4769
s-4771-jp
cef-windows-4771
syslog-4769-ch
cef-windows-4776
emc-syslog-4768
json-4768-1
json-4768-2
q-680
raw-680
wls-4768
wls-4769
raw-4769
raw-4768
s-4768-jp
logstash-4769
json-4776-1
logstash-4768
windows-events-4769
s-680
json-4776-2
wls-675
json-4769-2
syslog-4768-ch
raw-4769-1
wls-4776
exalms-680
wls-4771
r-nic-4771
raw-4769-5
s-673
n-forwarded-cef-680
raw-4769-4
raw-4769-3
s-675
raw-4769-2
raw-4769-7
raw-4769-6
json-4769-1
s-672
ad-audit-4769
evntslog-672
evntslog-675
q-675
syslog-4776-ch
q-672
cef-snare-4769
q-673
extrahop-4771
raw-4768-2
evntslog-680
raw-4768-1
raw-4768-5
raw-4768-4
greenbay-4776
raw-4768-3
s-4769-jp
cef-673
cef-672
extrahop-4768
extrahop-4769
n-forwarded-cef-4776
raw-4776-1
syslog-4776-multiline
mcafee-siem-4768
raw-4776-5
mcafee-siem-4769
raw-4776-4
raw-4776-3
raw-4776-2
mcafee-siem-4776
mcafee-siem-4771
n-forwarded-cef-4771
raw-675
raw-672
raw-673
xml-4769-1
windows-events-4776
n-forwarded-cef-4769
n-forwarded-cef-4768
u-680
json-4768
json-4769
windows-4768-1
s-xml-4771
exalms-4776
cef-4768
raw-4771-2
cef-4769
s-4776-jp
json-xml-4771
xml-4776
json-4771
cef-windows-4769
cef-windows-4768
json-xml-4769
json-xml-4768
json-4776
s-4625-jp
cef-4625
s-windows-4625
exalms-4625
syslog-4625-ch
rs-4625
s-windows-event-534
wls-4625
xml-4625
wazuh-4625
xml-4625-1
json-4625-1
mcafee-siem-4625
n-forwarded-cef-4625
json-4625-2
raw-4625
json-4625
spanish-raw-4625
emc-syslog-4625
raw-failed-logon-2003
s-windows-event-4625
cef-windows-4625
n-forwarded-cef-failed-logon-2003
raw-4625-1
ad-audit-json-4771
ad-audit-4771
ad-audit-4625
json-windows-events-netlogon
raw-5805
xml-4825
xml-1310

failed-vpn-login
json-windows-vpn-login

kerberos-logon
raw-672
json-4768-3
syslog-4768-ch
xml-4768
raw-4768-2
n-forwarded-cef-4768
raw-4768-1
raw-4768-5
json-4768
raw-4768-4
raw-4768-3
emc-syslog-4768
windows-4768-1
json-4768-1
cef-672
json-4768-2
s-672
extrahop-4768
cef-4768
evntslog-672
wls-4768
mcafee-siem-4768
raw-4768
s-4768-jp
q-672
logstash-4768
cef-windows-4768
json-xml-4768
ad-audit-4768
ad-audit-json-4768

local-logon
s-4624-jp
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
raw-4624-6
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
mcafee-siem-4624
wls-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
raw-4624-2
raw-4624-1
s-4624-jp
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
raw-4624-6
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-4624
cef-528
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
mcafee-siem-4624
wls-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
raw-4624-2
raw-4624-1
windows-rdp-login

member-added
json-member-added-2008
wls-member-added-2008-notype
emc-syslog-member-added-2008
s-member-added-2008-jp
n-forwarded-cef-member-added-2008
sk4-json-member-added-2008
ad-json-member-added-2008
raw-member-added-2003
s-member-added-2003
json-4728
s-member-added-2008
snare-cef-member-added-2008
syslog-json-member-added-2008
u-member-added-2008
raw-member-added-2008
l-member-added-2008
cef-windows-member-added-2003
cef-member-added-2008
q-member-added-2008
cef-member-added-2003
windows-xml-member-added-2008
jp-member-added-3
jp-member-added-1
jp-member-added-2
s-windows-event-636
evntslog-member-added-2003
s-windows-event-4728
s-xml-windows-member-3
s-xml-windows-member-1
s-xml-windows-member-2
s-xml-windows-member-4756
s-windows-event-4732
ad-audit-4728

member-removed
nic-member-removed-2008
s-member-removed-2003
s-windows-event-633
ad-json-member-removed-2008
s-windows-event-4729
cef-member-removed-2008
s-member-removed-2008
raw-member-removed-2008
raw-member-removed-2008-2
sk4-json-member-removed-2008
raw-member-removed-2008-3
raw-member-removed-2008-1
q-member-removed-2003
raw-member-removed-2003
n-forwarded-cef-member-removed-2008
cef-windows-member-removed-2003
u-member-removed-2008
json-4729
xml-member-removed-2008
s-windows-event-637
s-windows-event-4733
nic-member-removed-2003
q-member-removed-2008
json-member-removed
s-xml-windows-member-4757
s-xml-windows-member-4
s-xml-windows-member-5
s-xml-windows-member-6
ad-audit-4729

nac-logon
q-6272
json-6272
json-6272-1
xml-6272
xml-nps-logon

ntlm-logon
cef-4776
raw-4776
cef-snare-680
wazuh-4776
s-windows-4776
evntslog-680
wls-4776
exalms-680
u-680
n-forwarded-cef-680
greenbay-4776
cef-windows-4776
q-680
exalms-4776
s-4776-jp
raw-680
n-forwarded-cef-4776
raw-4776-1
syslog-4776-multiline
xml-4776
raw-4776-5
raw-4776-4
raw-4776-3
raw-4776-2
mcafee-siem-4776
syslog-4776-ch
emc-syslog-4776
json-4776-1
s-680
json-4776-2
json-4776
xml-windows-ntlm-logon-8001
xml-windows-ntlm-logon-8003
xml-windows-ntlm-logon-8002

privileged-access
l-4673
l-4672
s-windows-event-576
s-4672-jp
raw-4673
raw-4672
snare-576
snare-577
cef-4672
wazuh-4673
windows-events-4672
s-windows-4672
cef-4673
s-windows-4673
cef-windows-4673
raw-4672-2
raw-4673-1
s-576
raw-4672-1
raw-4673-2
raw-4672-3
wls-windows-privileged-access
cef-576
cef-snare-4673
exalms-576
xml-4672
json-4672-1
json-4673-1
json-4672-2
cef-snare-576
xml-4673
json-xml-4673
cef-snare-577
json-4673-2
spanish-raw-4672
s-windows-event-4672
s-windows-event-4673
mcafee-siem-4672
n-forwarded-cef-4673
n-forwarded-cef-4672
greenbay-privileged-access
json-4672
json-4673
emc-syslog-4673
emc-syslog-4672

privileged-object-access
s-4674-jp
raw-4674
cef-4674
exalms-4674
xml-4674
s-windows-event-578
snare-578
windows-xml-4674
cef-snare-578
s-windows-4674
xml-4674-1
s-windows-event-4674
cef-windows-4674
raw-4674-5
raw-4674-2
json-4674
l-4674
emc-syslog-4674
raw-4674-1
wls-windows-privileged-access
raw-4674-4
raw-4674-3

remote-access
json-4769-2
raw-673
xml-4769-1
n-forwarded-cef-4769
raw-4769-1
xml-4769
raw-4769-5
s-673
raw-4769-4
raw-4769-3
json-4769
raw-4769-2
emc-syslog-4769
syslog-4769-ch
raw-4769-7
s-4769-jp
raw-4769-6
cef-673
json-4769-1
ad-audit-4769
extrahop-4769
cef-4769
evntslog-673
wls-4769
mcafee-siem-4769
raw-4769
logstash-4769
cef-snare-4769
cef-windows-4769
q-673
windows-events-4769
json-xml-4769
raw-674
nic-4770
s-4770-jp
raw-4770
n-forwarded-cef-4770
raw-4770-1
mcafee-siem-4770
json-xml-4770
json-4770
extrahop-4770
s-xml-4770
cef-4770
s-4624-jp
exalms-540
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
r-nic-540
raw-4624-6
raw-540
s-windows-event-540
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
n-forwarded-cef-540
mcafee-siem-4624
wls-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
cef-540
raw-4624-2
raw-4624-1
s-4624-jp
exalms-540
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
ad-audit-json-4624
raw-4624-7
r-nic-540
raw-4624-6
raw-540
raw-4624-5
s-windows-event-540
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
n-forwarded-cef-540
mcafee-siem-4624
wls-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
cef-540
raw-4624-2
raw-4624-1
s-4624-jp
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
raw-4624-6
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
mcafee-siem-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
raw-4624-2
raw-4624-1
s-4624-jp
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
raw-4624-6
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
mcafee-siem-4624
wls-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
raw-4624-2
raw-4624-1
raw-552
s-windows-event-552
json-4648-1
n-forwarded-cef-4648
n-forwarded-cef-552
xml-4648
json-4648
json-4648-2
emc-syslog-4648
s-windows-event-4648
s-4648-jp
exalms-552
raw-4648-2
syslog-4648
cef-4648
raw-4648-3
s-windows-4648
raw-4648-4
cef-snare-552
raw-4648-5
mcafee-siem-4648
raw-4648
cef-snare-4648
raw-4648-1
windows-events-4648

remote-logon
raw-674
nic-4770
s-4770-jp
raw-4770
n-forwarded-cef-4770
raw-4770-1
mcafee-siem-4770
json-xml-4770
json-4770
extrahop-4770
s-xml-4770
cef-4770
s-4624-jp
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
raw-4624-6
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
mcafee-siem-4624
wls-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
raw-4624-2
raw-4624-1
s-4624-jp
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
raw-4624-6
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
mcafee-siem-4624
wls-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
raw-4624-2
raw-4624-1
json-4778
xml-4778
raw-4778
s-windows-event-4778
raw-4778-1
mcafee-siem-4778
raw-552
s-windows-event-552
json-4648-1
n-forwarded-cef-4648
n-forwarded-cef-552
xml-4648
json-4648
json-4648-2
emc-syslog-4648
s-windows-event-4648
s-4648-jp
exalms-552
raw-4648-2
syslog-4648
cef-4648
raw-4648-3
s-windows-4648
raw-4648-4
cef-snare-552
raw-4648-5
mcafee-siem-4648
raw-4648
cef-snare-4648
raw-4648-1
windows-events-4648
ad-audit-4778
windows-rdp-login
raw-1149-1
xml-1149
raw-1149

vpn-login
json-windows-vpn-login
s-xml-windows-member-11
s-xml-windows-member-9
s-xml-windows-member-13
s-xml-windows-member-7

vpn-logout
s-xml-windows-member-10
s-xml-windows-member-14
s-xml-windows-member-8

workstation-unlocked
s-4624-jp
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
raw-4624-6
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
mcafee-siem-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
raw-4624-2
raw-4624-1
s-4624-jp
rs-4624
xml-4624
xml-4624-1
json-4624-2
n-forwarded-cef-4624
json-4624-1
json-4624
evntslog-528
nic-528
emc-syslog-4624
s-windows-event-528
s-windows-event-4624
raw-4624-7
raw-4624-6
raw-4624-5
raw-4624-4
windows-events-4624
n-forwarded-cef-528
raw-4624-9
cef-528
cef-4624
raw-4624-8
wazuh-4624
r-nic-528
raw-4624
mcafee-siem-4624
raw-4624-10
cef-windows-4624
raw-528
logstash-4624
cef-snare-4624
raw-4624-3
raw-4624-2
raw-4624-1
s-4801
cef-4801
s-4801-1
q-4801
sk4-json-4801
xml-4801
s-windows-event-4801
raw-4801
ad-audit-4801
T1021 - Remote Services
T1078 - Valid Accounts
T1078.002 - T1078.002
T1078.003 - Valid Accounts: Local Accounts
T1110 - Brute Force
T1133 - External Remote Services
  • 70 Rules
  • 26 Models
Account Manipulationaccount-creation
syslog-json-4720
cef-4720
cef-windows-account-4720
sk4-json-4720
s-xml-4720
raw-windows-account-624
wls-4720
s-4720-jp
mcafee-siem-4720
windows-xml-4720
raw-windows-account-4720
cef-624
ad-json-4720
json-4720-1
json-4720
l-4720
ad-audit-4720

account-deleted
s-xml-4726
raw-windows-account-4726
json-4726
s-4726-jp
nxlog-json-4726
wls-4726
mcafee-siem-4726
raw-windows-account-630
ad-audit-4726
raw-4743
raw-4743-1
ad-audit-4743
raw-4743-2

account-password-change
s-xml-4723
syslog-json-4723
cef-4723
s-627
raw-4723
mcafee-siem-4723
wls-4723
json-4723
nic-627
emc-syslog-4723
wls-627
l-4723
raw-627
s-4723-jp
s-windows-event-4723
s-windows-event-627
json-4723-1
json-4723-2
ad-audit-4723

account-password-reset
s-xml-4724
syslog-json-4724
cef-4724
ad-json-4724
wls-4724
sk4-json-4724
mcafee-siem-4724
q-628
n-forwarded-cef-4724
raw-4724
json-4724
raw-628
s-windows-event-4724
l-4724
s-4724-jp
json-4724-1
json-4724-2
ad-audit-4724

ds-access
cef-snare-5136
xml-5137
xml-5138
sk4-json-5137
xml-5136
raw-4738
s-5137
xml-5139
n-forwarded-cef-5136
nic-5141
s-5141-1
mcafee-siem-5137
mcafee-siem-5136
s-windows-event-4780
json-xml-5141
nic-5136
wazuh-4738
nic-5137
json-5136
ad-audit-5139
raw-5138
json-4738-1
raw-5139
raw-5136
json-4738-2
s-5141
raw-5137
cef-5136
xml-4738
cef-windows-ds-access-5137
json-4738
r-syslog-5136
raw-5141
mcafee-siem-5141
json-5136-1
xml-5141
sk4-json-5141
jp-4662
exalms-4742
raw-4742
xml-4742-jp
sk4-json-4662
json-4662-1
raw-4662
xml-4662
exalms-4662
raw-4662-1
n-forwarded-cef-4662
windows-xml-4742
s-4662
cef-windows-4742
xml-4662-jp
json-4662
q-4662
raw-4662-2
raw-4662-3
ad-audit-5141
ad-audit-4738
ad-audit-5136
ad-audit-4662
ad-audit-5137
ad-audit-4742
raw-4929
raw-4928

member-added
json-member-added-2008
wls-member-added-2008-notype
emc-syslog-member-added-2008
s-member-added-2008-jp
n-forwarded-cef-member-added-2008
sk4-json-member-added-2008
ad-json-member-added-2008
raw-member-added-2003
s-member-added-2003
json-4728
s-member-added-2008
snare-cef-member-added-2008
syslog-json-member-added-2008
u-member-added-2008
raw-member-added-2008
l-member-added-2008
cef-windows-member-added-2003
cef-member-added-2008
q-member-added-2008
cef-member-added-2003
windows-xml-member-added-2008
jp-member-added-3
jp-member-added-1
jp-member-added-2
s-windows-event-636
evntslog-member-added-2003
s-windows-event-4728
s-xml-windows-member-3
s-xml-windows-member-1
s-xml-windows-member-2
s-xml-windows-member-4756
s-windows-event-4732
ad-audit-4728

member-removed
nic-member-removed-2008
s-member-removed-2003
s-windows-event-633
ad-json-member-removed-2008
s-windows-event-4729
cef-member-removed-2008
s-member-removed-2008
raw-member-removed-2008
raw-member-removed-2008-2
sk4-json-member-removed-2008
raw-member-removed-2008-3
raw-member-removed-2008-1
q-member-removed-2003
raw-member-removed-2003
n-forwarded-cef-member-removed-2008
cef-windows-member-removed-2003
u-member-removed-2008
json-4729
xml-member-removed-2008
s-windows-event-637
s-windows-event-4733
nic-member-removed-2003
q-member-removed-2008
json-member-removed
s-xml-windows-member-4757
s-xml-windows-member-4
s-xml-windows-member-5
s-xml-windows-member-6
ad-audit-4729

process-created
mcafee-siem-process-created
cef-4688
u-4688
cef-snare-4688
n-forwarded-cef-4688
json-process-created
s-windows-4688
l-4688-v2
xml-4688
wls-4688
raw-process-created-1
cef-snare-process-created
json-process-created-1
snare-592
json-process-created-2
s-windows-process-created
nic-4688
spanish-raw-4688
emc-syslog-4688
raw-process-created
s-4688-jp
s-592
s-windows-event-4688
cef-powershell-300
raw-4104
cef-powershell-600
xml-powershell-4104
powershell-800-syslog
windows-powershell-800
powershell-process-created
powershell-800
win-powershell-command
powershell-process-created-1
powershell-process-created-2
cef-windows-4104
raw-powershell-600
windows-xml-powershell-process-created
powershell-800-syslog-1
windows-xml-powershell-process-created-2
cef-powershell-4104
s-windows-event-601
windows-xml-powershell-process-created-1
cef-powershell-4102
powershell-4104
json-4104
windows-xml-powershell-800
ad-audit-4688
xml-5861
cef-azure-process-created

vpn-logout
s-xml-windows-member-10
s-xml-windows-member-14
s-xml-windows-member-8
T1003 - OS Credential Dumping
T1003.003 - T1003.003
T1021.003 - T1021.003
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.003 - T1059.003
T1078 - Valid Accounts
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
T1207 - Rogue Domain Controller
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1484 - Group Policy Modification
T1531 - Account Access Removal
T1559.002 - T1559.002
  • 97 Rules
  • 47 Models
Physical Securityvpn-login
json-windows-vpn-login
s-xml-windows-member-11
s-xml-windows-member-9
s-xml-windows-member-13
s-xml-windows-member-7
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

Replication Through Removable Media

Phishing

Windows Management Instrumentation

Command and Scripting Interperter

Scheduled Task/Job

Inter-Process Communication

System Services

Exploitation for Client Execution

User Execution

Scheduled Task/Job: Scheduled Task

Command and Scripting Interperter: PowerShell

Scheduled Task/Job: At (Windows)

Pre-OS Boot

Create Account

Create or Modify System Process

External Remote Services

Valid Accounts

Hijack Execution Flow

Server Software Component: Web Shell

Account Manipulation

BITS Jobs

Create or Modify System Process: Windows Service

Scheduled Task/Job

Server Software Component

Event Triggered Execution

Boot or Logon Autostart Execution

Create Account: Create: Local Account

Account Manipulation: Exchange Email Delegate Permissions

Access Token Manipulation: Token Impersonation/Theft

Create or Modify System Process

Valid Accounts

Access Token Manipulation

Exploitation for Privilege Escalation

Hijack Execution Flow

Group Policy Modification

Process Injection

Scheduled Task/Job

Abuse Elevation Control Mechanism

Event Triggered Execution

Boot or Logon Autostart Execution

Process Injection: Dynamic-link Library Injection

Abuse Elevation Control Mechanism: Bypass User Account Control

Hide Artifacts

Indirect Command Execution

Impair Defenses

Indicator Removal on Host: Clear Windows Event Logs

Group Policy Modification

Rogue Domain Controller

Trusted Developer Utilities Proxy Execution

Masquerading: Match Legitimate Name or Location

Masquerading: Rename System Utilities

File and Directory Permissions Modification: Windows File and Directory Permissions Modification

Obfuscated Files or Information: Compile After Delivery

Obfuscated Files or Information: Indicator Removal from Tools

Hijack Execution Flow: DLL Side-Loading

Indicator Removal on Host: File Deletion

Masquerading

Valid Accounts

Modify Registry

BITS Jobs

Use Alternate Authentication Material

Hide Artifacts: NTFS File Attributes

Use Alternate Authentication Material: Pass the Hash

Indicator Removal on Host

Use Alternate Authentication Material: Pass the Ticket

Pre-OS Boot

File and Directory Permissions Modification

Deobfuscate/Decode Files or Information

Abuse Elevation Control Mechanism

Impair Defenses: Disable or Modify System Firewall

Obfuscated Files or Information

Signed Binary Proxy Execution: Compiled HTML File

Access Token Manipulation

Hijack Execution Flow

Process Injection

Valid Accounts: Local Accounts

Signed Binary Proxy Execution: Msiexec

Signed Binary Proxy Execution

Signed Binary Proxy Execution: Regsvcs/Regasm

Signed Binary Proxy Execution: CMSTP

Signed Binary Proxy Execution: Control Panel

Signed Binary Proxy Execution: InstallUtil

Signed Binary Proxy Execution: Regsvr32

Trusted Developer Utilities Proxy Execution: MSBuild

Signed Binary Proxy Execution: Rundll32

OS Credential Dumping

Unsecured Credentials

Brute Force

Forced Authentication

Steal or Forge Kerberos Tickets

Credentials from Password Stores

Steal or Forge Kerberos Tickets: Kerberoasting

OS Credential Dumping: DCSync

Network Sniffing

Account Discovery

Domain Trust Discovery

System Service Discovery

System Network Connections Discovery

Account Discovery: Local Account

Account Discovery: Domain Account

File and Directory Discovery

Network Sniffing

System Information Discovery

Network Share Discovery

Query Registry

Process Discovery

System Owner/User Discovery

Software Discovery

Remote System Discovery

System Network Configuration Discovery

Exploitation of Remote Services

Remote Service Session Hijacking

Remote Services

Remote Services: SMB/Windows Admin Shares

Use Alternate Authentication Material

Remote Services: Remote Desktop Protocol

Replication Through Removable Media

Screen Capture

Email Collection

Audio Capture

Archive Collected Data

Protocol Tunneling

Application Layer Protocol: DNS

Application Layer Protocol: File Transfer Protocols

Application Layer Protocol: Web Protocols

Remote Access Software

Dynamic Resolution

Ingress Tool Transfer

Dynamic Resolution: Domain Generation Algorithms

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol

Exfiltration Over Physical Medium: Exfiltration over USB

Exfiltration Over C2 Channel

Exfiltration Over Physical Medium

Account Access Removal

Data Destruction

Resource Hijacking

Data Encrypted for Impact

Inhibit System Recovery