Vendor: Onapsis

June 14, 2023 · View on GitHub

Product: Onapsis

Use-Case: Privilege Abuse

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
20122
Event TypeRulesModels
app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
APP-F-SA-NC: New service account access to application
failed-app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account