Vendor: SFTP

June 14, 2023 · View on GitHub

Product: SFTP

Use-Case: Privileged Activity

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
20177
Event TypeRulesModels
app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
failed-app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
file-deleteT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-downloadT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-readT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-uploadT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-writeT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account