Vendor: RSA

June 14, 2023 · View on GitHub

Product: RSA DLP

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
7036722
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Data Exfiltrationdlp-alert
rsa-dlp-alert
T1020 - Automated Exfiltration
T1071 - Application Layer Protocol
TA0010 - TA0010
  • 29 Rules
  • 18 Models
Data Leakdlp-alert
rsa-dlp-alert

dlp-email-alert-out
rsa-dlp-email-alert
T1020 - Automated Exfiltration
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1071 - Application Layer Protocol
TA0010 - TA0010
  • 61 Rules
  • 33 Models
Malwaredlp-alert
rsa-dlp-alert

dlp-email-alert-out
rsa-dlp-email-alert
T1190 - Exploit Public Fasing Application
TA0002 - TA0002
  • 5 Rules
  • 2 Models
Phishingdlp-email-alert-out
rsa-dlp-email-alert
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 1 Rules
  • 1 Models
Privilege Abusedlp-email-alert-out
rsa-dlp-email-alert
T1078 - Valid Accounts
  • 1 Rules
Privileged Activitydlp-email-alert-out
rsa-dlp-email-alert
T1078 - Valid Accounts
  • 1 Rules
Workforce Protectiondlp-email-alert-out
rsa-dlp-email-alert
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 4 Rules
  • 1 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Exploit Public Fasing Application

Valid Accounts

Valid Accounts

Valid Accounts

Application Layer Protocol

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol

Automated Exfiltration