Vendor: Tanium

June 14, 2023 · View on GitHub

Product: Threat Response

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
3711511
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Compromised Credentialsprocess-alert
tanium-process-alert
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
TA0002 - TA0002
  • 7 Rules
  • 2 Models
Malwareprocess-alert
tanium-process-alert
T1053.003 - T1053.003
T1190 - Exploit Public Fasing Application
T1562.004 - Impair Defenses: Disable or Modify System Firewall
TA0002 - TA0002
  • 32 Rules
  • 10 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Exploit Public Fasing Application

Scheduled Task/Job

Scheduled Task/Job

Scheduled Task/Job

Impair Defenses

Obfuscated Files or Information: Indicator Removal from Tools

Impair Defenses: Disable or Modify System Firewall

Obfuscated Files or Information