Vendor: Sailpoint

June 14, 2023 · View on GitHub

Product: SecurityIQ

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
9737181212
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-creation
s-sailpointsiq-ad-account-creation

account-deleted
s-sailpointsiq-ad-account-deleted

account-lockout
s-sailpointsiq-ad-account-lockout

account-password-reset
s-sailpointsiq-ad-account-passwd-reset

member-added
s-sailpointsiq-windowsfs-member-added

member-removed
s-sailpointsiq-windowsfs-member-removed
T1078 - Valid Accounts
T1110 - Brute Force
  • 4 Rules
  • 1 Models
Account Manipulationaccount-creation
s-sailpointsiq-ad-account-creation

account-deleted
s-sailpointsiq-ad-account-deleted

account-password-reset
s-sailpointsiq-ad-account-passwd-reset

member-added
s-sailpointsiq-windowsfs-member-added

member-removed
s-sailpointsiq-windowsfs-member-removed
T1098 - Account Manipulation
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
T1531 - Account Access Removal
  • 44 Rules
  • 18 Models
Brute Force Attackaccount-lockout
s-sailpointsiq-ad-account-lockout
T1110 - Brute Force
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Create Account

Valid Accounts

Server Software Component: Web Shell

Account Manipulation

Server Software Component

Boot or Logon Autostart Execution

Create Account: Create: Local Account

Valid Accounts

Boot or Logon Autostart Execution

Indicator Removal on Host: File Deletion

Valid Accounts

Indicator Removal on Host

OS Credential Dumping

Brute Force

File and Directory Discovery

Email Collection

Account Access Removal

Data Destruction

Data Encrypted for Impact