Vendor: Sailpoint
June 14, 2023 · View on GitHub
Product: SecurityIQ
| Rules | Models | MITRE ATT&CK® TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 97 | 37 | 18 | 12 | 12 |
MITRE ATT&CK® Framework for Enterprise
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts | Create Account Valid Accounts Server Software Component: Web Shell Account Manipulation Server Software Component Boot or Logon Autostart Execution Create Account: Create: Local Account | Valid Accounts Boot or Logon Autostart Execution | Indicator Removal on Host: File Deletion Valid Accounts Indicator Removal on Host | OS Credential Dumping Brute Force | File and Directory Discovery | Email Collection | Account Access Removal Data Destruction Data Encrypted for Impact |