Vendor: SkySea

June 14, 2023 · View on GitHub

Product: ClientView

Use-Case: Privileged Activity

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
8151212
Event TypeRulesModels
app-activityT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
APP-AT-PRIV: Non-privileged user performing privileged application activity
APP-AT-PRIV: Privileged application activities
app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
dlp-email-alert-outT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
file-deleteT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-downloadT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-readT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-uploadT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-writeT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
process-createdT1482 - Domain Trust Discovery
A-Trickbot-Recon: Trickbot malware domain recon activity on this asset
Trickbot-Recon: Trickbot malware domain recon activity
security-alertT1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
web-activity-allowedT1071.001 - Application Layer Protocol: Web Protocols
A-WEB-DC: Web activity event on a Domain Controller
WEB-ALERT-EXEC: Security violation by Executive in web activity

T1078 - Valid Accounts
WEB-ALERT-EXEC: Security violation by Executive in web activity

T1102 - Web Service
A-WEB-DC: Web activity event on a Domain Controller
web-activity-deniedT1071.001 - Application Layer Protocol: Web Protocols
A-WEB-DC: Web activity event on a Domain Controller
WEB-ALERT-EXEC: Security violation by Executive in web activity

T1078 - Valid Accounts
WEB-ALERT-EXEC: Security violation by Executive in web activity

T1102 - Web Service
A-WEB-DC: Web activity event on a Domain Controller