Vendor: SecureNet

June 14, 2023 · View on GitHub

Product: SecureNet

Use-Case: Privilege Abuse

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
32322
Event TypeRulesModels
vpn-loginT1078 - Valid Accounts
SL-UA-F-VPN: First VPN connection for service account

T1133 - External Remote Services
SL-UA-F-VPN: First VPN connection for service account
vpn-logoutT1098.002 - Account Manipulation: Exchange Email Delegate Permissions
EM-InB-Perm-A: Abnormal number of mailbox permission given by user.

T1078 - Valid Accounts
WPA-UACount: Abnormal number of privilege access events for user
EM-InB-Perm: Models the number of mailbox permissions given by this user.
WPA-UACount: Count of admin privilege events for user