Vendor: OneSpan

June 14, 2023 · View on GitHub

Product: OneSpan

Use-Case: Lateral Movement

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
141811
Event TypeRulesModels
failed-logonT1550.002 - Use Alternate Authentication Material: Pass the Hash
A-PTH-ALERT-sH-Failed: Failed pass the hash attack with keylength of 0 in NTLM event and a 'null' sid on this source host.
FAIL-PTH-ALERT-sH: Possible unsuccessful pass the hash attack from the source
FAIL-PTH-ALERT-dH: Possible unsuccessful pass the hash attack by the user
PTH-ALERT-sH-Failed: Failed pass the hash attack with keylength of 0 in NTLM event and a 'null' sid.

T1021.001 - Remote Services: Remote Desktop Protocol
RDP-Brute-Force: Abnormal number of RDP failed logons for this user

T1110 - Brute Force
A-FL-MULTI-USERS-S: Multiple users failed to login (S)
A-FL-MULTI-USERS-L: Multiple users failed to login (L)
A-FL-MULTI-USERS-M: Multiple users failed to login (M)
A-FL-MULTI-DEST-S: Failed logins to multiple destinations from host (S)
A-FL-MULTI-DEST-M: Failed logins to multiple destinations from host (M)
RDP-Brute-Force: Abnormal number of RDP failed logons for this user

T1078 - Valid Accounts
Auth-Tor-Shost-Failed: User authentication or login failure from a known TOR IP

T1090.003 - Proxy: Multi-hop Proxy
Auth-Tor-Shost-Failed: User authentication or login failure from a known TOR IP

T1550.003 - Use Alternate Authentication Material: Pass the Ticket
KL-TfG: Rare Kerberos ticket failure code
KL-Tf-fail: Failed logon due to a malformed authentication ticket

T1558 - Steal or Forge Kerberos Tickets
KL-TfG: Rare Kerberos ticket failure code
KL-Tf-fail: Failed logon due to a malformed authentication ticket

T1110.003 - T1110.003
A-FL-MULTI-USERS-SRC: The same host failed to login to multiple users
AE-OHr: Random hostnames