Vendor: NetskopeJune 14, 2023 · View on GitHubProduct: Security Cloud RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers344136351616 Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContentAbnormal Authentication & Accessapp-activity ↳netskope-activity ↳netskope-app-activity-2 ↳netskope-app-activity-1 ↳s-netskope-activity ↳cef-netskope-app-activity-22 ↳cef-netskope-app-activity-24 ↳cef-netskope-app-activity-23 ↳cef-netskope-app-activity-19 ↳cef-netskope-app-activity-18 ↳cef-netskope-app-activity-15 ↳cef-netskope-app-activity-14 ↳cef-netskope-app-activity-17 ↳cef-netskope-app-activity-16 ↳cef-netskope-app-activity-8 ↳cef-netskope-app-activity-11 ↳cef-netskope-app-activity-7 ↳cef-netskope-app-activity-10 ↳cef-netskope-app-activity-6 ↳cef-netskope-app-activity-13 ↳cef-netskope-app-activity-5 ↳cef-netskope-app-activity-12 ↳cef-netskope-app-activity-51 ↳cef-netskope-app-activity-50 ↳cef-netskope-app-activity-9 ↳json-netskope-app-activity-17 ↳cef-netskope-app-activity-4 ↳cef-netskope-app-activity-3 ↳cef-netskope-app-activity-2 ↳cef-netskope-app-activity-1 ↳cef-netskope-app-activity-48 ↳cef-netskope-app-activity-47 ↳cef-netskope-app-activity-49 ↳cef-netskope-app-activity-44 ↳cef-netskope-app-activity-43 ↳cef-netskope-app-activity-46 ↳cef-netskope-app-activity-45 ↳cef-netskope-app-activity-40 ↳cef-netskope-app-activity-42 ↳cef-netskope-app-activity-41 ↳json-netskope-app-activity-18 ↳cef-netskope-app-activity-37 ↳cef-netskope-app-activity-36 ↳cef-netskope-app-activity-38 ↳cef-netskope-app-activity-33 ↳cef-netskope-app-activity-35 ↳cef-netskope-app-activity-34 ↳cef-netskope-app-activity-31 ↳cef-netskope-app-activity-29 ↳cef-netskope-app-activity-26 ↳cef-netskope-app-activity-25 ↳cef-netskope-app-activity-28 ↳cef-netskope-app-activity-27 ↳netskope-app-activity app-login ↳cef-netskope-app-login-1 ↳cef-netskope-app-login-2 ↳json-netskope-app-login ↳netskope-login ↳s-netskope-login ↳netskope-login-1 failed-app-login ↳cef-netskope-failed-app-login ↳json-netskope-failed-app-login web-activity-allowed ↳cef-netskope-web-activity-1 ↳cef-netskope-web-activity ↳netskope-web-activity web-activity-denied ↳netskope-web-activity ↳cef-netskope-web-policy ↳cef-netskope-web-policy-1T1071.001 - Application Layer Protocol: Web ProtocolsT1078 - Valid AccountsT1133 - External Remote Services21 Rules10 ModelsAccount Manipulationapp-activity ↳netskope-activity ↳netskope-app-activity-2 ↳netskope-app-activity-1 ↳s-netskope-activity ↳cef-netskope-app-activity-22 ↳cef-netskope-app-activity-24 ↳cef-netskope-app-activity-23 ↳cef-netskope-app-activity-19 ↳cef-netskope-app-activity-18 ↳cef-netskope-app-activity-15 ↳cef-netskope-app-activity-14 ↳cef-netskope-app-activity-17 ↳cef-netskope-app-activity-16 ↳cef-netskope-app-activity-8 ↳cef-netskope-app-activity-11 ↳cef-netskope-app-activity-7 ↳cef-netskope-app-activity-10 ↳cef-netskope-app-activity-6 ↳cef-netskope-app-activity-13 ↳cef-netskope-app-activity-5 ↳cef-netskope-app-activity-12 ↳cef-netskope-app-activity-51 ↳cef-netskope-app-activity-50 ↳cef-netskope-app-activity-9 ↳json-netskope-app-activity-17 ↳cef-netskope-app-activity-4 ↳cef-netskope-app-activity-3 ↳cef-netskope-app-activity-2 ↳cef-netskope-app-activity-1 ↳cef-netskope-app-activity-48 ↳cef-netskope-app-activity-47 ↳cef-netskope-app-activity-49 ↳cef-netskope-app-activity-44 ↳cef-netskope-app-activity-43 ↳cef-netskope-app-activity-46 ↳cef-netskope-app-activity-45 ↳cef-netskope-app-activity-40 ↳cef-netskope-app-activity-42 ↳cef-netskope-app-activity-41 ↳json-netskope-app-activity-18 ↳cef-netskope-app-activity-37 ↳cef-netskope-app-activity-36 ↳cef-netskope-app-activity-38 ↳cef-netskope-app-activity-33 ↳cef-netskope-app-activity-35 ↳cef-netskope-app-activity-34 ↳cef-netskope-app-activity-31 ↳cef-netskope-app-activity-29 ↳cef-netskope-app-activity-26 ↳cef-netskope-app-activity-25 ↳cef-netskope-app-activity-28 ↳cef-netskope-app-activity-27 ↳netskope-app-activityT1098.002 - Account Manipulation: Exchange Email Delegate Permissions3 Rules1 ModelsCryptominingweb-activity-allowed ↳cef-netskope-web-activity-1 ↳cef-netskope-web-activity ↳netskope-web-activity web-activity-denied ↳netskope-web-activity ↳cef-netskope-web-policy ↳cef-netskope-web-policy-1T1071.001 - Application Layer Protocol: Web ProtocolsT1496 - Resource Hijacking2 RulesDestruction of Datafile-delete ↳netskope-activity ↳s-netskope-activityT1070.004 - Indicator Removal on Host: File DeletionT1485 - Data Destruction1 RulesWorkforce Protectiondlp-email-alert-out ↳cef-netskope-dlp-email-alert-1 web-activity-allowed ↳cef-netskope-web-activity-1 ↳cef-netskope-web-activity ↳netskope-web-activityT1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolT1071.001 - Application Layer Protocol: Web Protocols8 Rules3 ModelsNext Page -->> MITRE ATT&CK® Framework for Enterprise Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpactPhishing: Spearphishing LinkExternal Remote ServicesValid AccountsDrive-by CompromiseExploit Public Fasing ApplicationPhishingUser ExecutionExternal Remote ServicesValid AccountsServer Software Component: Web ShellAccount ManipulationServer Software ComponentBoot or Logon Autostart ExecutionAccount Manipulation: Exchange Email Delegate PermissionsValid AccountsExploitation for Privilege EscalationBoot or Logon Autostart ExecutionObfuscated Files or Information: Indicator Removal from ToolsIndicator Removal on Host: File DeletionValid AccountsIndicator Removal on HostObfuscated Files or InformationOS Credential DumpingFile and Directory DiscoveryInternal SpearphishingEmail CollectionEmail Collection: Email Forwarding RuleWeb ServiceApplication Layer Protocol: Web ProtocolsDynamic ResolutionDynamic Resolution: Domain Generation AlgorithmsProxy: Multi-hop ProxyApplication Layer ProtocolProxyExfiltration Over Alternative ProtocolExfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolExfiltration Over C2 ChannelAutomated ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud StorageExfiltration Over Web ServiceData DestructionResource HijackingData Encrypted for Impact