Vendor: Semperis

June 14, 2023 · View on GitHub

Product: DSP

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
8836944
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessapp-login
semperis-dsp-app-login
semperis-dsp-app-login-1

failed-app-login
semperis-dsp-app-login

privileged-object-access
semperis-dsp-privileged-object-access
T1078 - Valid Accounts
T1133 - External Remote Services
  • 15 Rules
  • 4 Models
Account Manipulationds-access
semperis-dsp-ds-access-1
semperis-dsp-ds-access-3
semperis-dsp-ds-access-2
semperis-dsp-ds-access
T1207 - Rogue Domain Controller
T1484 - Group Policy Modification
  • 31 Rules
  • 16 Models
Compromised Credentialsapp-login
semperis-dsp-app-login
semperis-dsp-app-login-1

ds-access
semperis-dsp-ds-access-1
semperis-dsp-ds-access-3
semperis-dsp-ds-access-2
semperis-dsp-ds-access

failed-app-login
semperis-dsp-app-login
T1003.006 - OS Credential Dumping: DCSync
T1078 - Valid Accounts
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
T1207 - Rogue Domain Controller
T1558 - Steal or Forge Kerberos Tickets
  • 35 Rules
  • 17 Models
Data Accessapp-login
semperis-dsp-app-login
semperis-dsp-app-login-1

failed-app-login
semperis-dsp-app-login
T1078 - Valid Accounts
  • 6 Rules
  • 4 Models
Lateral Movementapp-login
semperis-dsp-app-login
semperis-dsp-app-login-1

failed-app-login
semperis-dsp-app-login
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
  • 2 Rules
Malwareapp-login
semperis-dsp-app-login
semperis-dsp-app-login-1

privileged-object-access
semperis-dsp-privileged-object-access
T1078 - Valid Accounts
TA0002 - TA0002
  • 5 Rules
  • 2 Models
Privilege Abuseapp-login
semperis-dsp-app-login
semperis-dsp-app-login-1

ds-access
semperis-dsp-ds-access-1
semperis-dsp-ds-access-3
semperis-dsp-ds-access-2
semperis-dsp-ds-access

failed-app-login
semperis-dsp-app-login
T1078 - Valid Accounts
T1484 - Group Policy Modification
  • 4 Rules
  • 2 Models
Privileged Activityapp-login
semperis-dsp-app-login
semperis-dsp-app-login-1

ds-access
semperis-dsp-ds-access-1
semperis-dsp-ds-access-3
semperis-dsp-ds-access-2
semperis-dsp-ds-access

failed-app-login
semperis-dsp-app-login
T1003.006 - OS Credential Dumping: DCSync
T1078 - Valid Accounts
T1207 - Rogue Domain Controller
T1484 - Group Policy Modification
  • 8 Rules
  • 2 Models
Ransomwareapp-login
semperis-dsp-app-login
semperis-dsp-app-login-1

failed-app-login
semperis-dsp-app-login
T1078 - Valid Accounts
  • 2 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Valid Accounts

Group Policy Modification

Group Policy Modification

Rogue Domain Controller

Valid Accounts

OS Credential Dumping

Steal or Forge Kerberos Tickets

OS Credential Dumping: DCSync

Proxy: Multi-hop Proxy

Proxy