Vendor: RS2

June 14, 2023 · View on GitHub

Product: RS2 Technologies

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
126111
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessfailed-physical-access
rs2-badge-failed-physical-access-1
rs2-badge-failed-physical-access-2
rs2-badge-access

physical-access
rs2-badge-access
rs2-badge-physical-access-2
rs2-badge-physical-access-1
T1078 - Valid Accounts
  • 3 Rules
  • 2 Models
Physical Securityfailed-physical-access
rs2-badge-failed-physical-access-1
rs2-badge-failed-physical-access-2
rs2-badge-access

physical-access
rs2-badge-access
rs2-badge-physical-access-2
rs2-badge-physical-access-1
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models
Privileged Activityfailed-physical-access
rs2-badge-failed-physical-access-1
rs2-badge-failed-physical-access-2
rs2-badge-access

physical-access
rs2-badge-access
rs2-badge-physical-access-2
rs2-badge-physical-access-1
T1078 - Valid Accounts
  • 1 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Valid Accounts

Valid Accounts

Valid Accounts