| Abnormal Authentication & Access | app-login ↳semperis-dsp-app-login ↳semperis-dsp-app-login-1
failed-app-login ↳semperis-dsp-app-login
privileged-object-access ↳semperis-dsp-privileged-object-access
| T1078 - Valid Accounts T1133 - External Remote Services
| |
| Account Manipulation | ds-access ↳semperis-dsp-ds-access-1 ↳semperis-dsp-ds-access-3 ↳semperis-dsp-ds-access-2 ↳semperis-dsp-ds-access
| T1207 - Rogue Domain Controller T1484 - Group Policy Modification
| |
| Compromised Credentials | app-login ↳semperis-dsp-app-login ↳semperis-dsp-app-login-1
ds-access ↳semperis-dsp-ds-access-1 ↳semperis-dsp-ds-access-3 ↳semperis-dsp-ds-access-2 ↳semperis-dsp-ds-access
failed-app-login ↳semperis-dsp-app-login
| T1003.006 - OS Credential Dumping: DCSync T1078 - Valid Accounts T1133 - External Remote Services T1190 - Exploit Public Fasing Application T1207 - Rogue Domain Controller T1558 - Steal or Forge Kerberos Tickets
| |
| Data Access | app-login ↳semperis-dsp-app-login ↳semperis-dsp-app-login-1
failed-app-login ↳semperis-dsp-app-login
| T1078 - Valid Accounts
| |
| Lateral Movement | app-login ↳semperis-dsp-app-login ↳semperis-dsp-app-login-1
failed-app-login ↳semperis-dsp-app-login
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy
| |
| Malware | app-login ↳semperis-dsp-app-login ↳semperis-dsp-app-login-1
privileged-object-access ↳semperis-dsp-privileged-object-access
| T1078 - Valid Accounts TA0002 - TA0002
| |
| Privilege Abuse | app-login ↳semperis-dsp-app-login ↳semperis-dsp-app-login-1
ds-access ↳semperis-dsp-ds-access-1 ↳semperis-dsp-ds-access-3 ↳semperis-dsp-ds-access-2 ↳semperis-dsp-ds-access
failed-app-login ↳semperis-dsp-app-login
| T1078 - Valid Accounts T1484 - Group Policy Modification
| |
| Privileged Activity | app-login ↳semperis-dsp-app-login ↳semperis-dsp-app-login-1
ds-access ↳semperis-dsp-ds-access-1 ↳semperis-dsp-ds-access-3 ↳semperis-dsp-ds-access-2 ↳semperis-dsp-ds-access
failed-app-login ↳semperis-dsp-app-login
| T1003.006 - OS Credential Dumping: DCSync T1078 - Valid Accounts T1207 - Rogue Domain Controller T1484 - Group Policy Modification
| |
| Ransomware | app-login ↳semperis-dsp-app-login ↳semperis-dsp-app-login-1
failed-app-login ↳semperis-dsp-app-login
| T1078 - Valid Accounts
| |