Vendor: SentinelOne
June 14, 2023 · View on GitHub
Product: Vigilance
| Rules | Models | MITRE ATT&CK® TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 121 | 45 | 13 | 5 | 5 |
MITRE ATT&CK® Framework for Enterprise
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
| External Remote Services Valid Accounts Exploit Public Fasing Application | Create Account External Remote Services Valid Accounts Account Manipulation Create Account: Create: Local Account Account Manipulation: Exchange Email Delegate Permissions | Valid Accounts Exploitation for Privilege Escalation | Obfuscated Files or Information: Indicator Removal from Tools Valid Accounts Obfuscated Files or Information | Email Collection Email Collection: Email Forwarding Rule | Proxy: Multi-hop Proxy Proxy |