Vendor: Unix

June 14, 2023 · View on GitHub

Product: Unix Privilege Management

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
169311
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-switch
upm-account-switch
T1078 - Valid Accounts
  • 2 Rules
  • 1 Models
Malwareaccount-switch
upm-account-switch
TA0002 - TA0002
  • 4 Rules
  • 2 Models
Privilege Abuseaccount-switch
upm-account-switch
T1078 - Valid Accounts
  • 2 Rules
Privilege Escalationaccount-switch
upm-account-switch
T1078 - Valid Accounts
T1555.005 - T1555.005
  • 10 Rules
  • 7 Models
Privileged Activityaccount-switch
upm-account-switch
T1078 - Valid Accounts
  • 1 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Valid Accounts

Valid Accounts

Valid Accounts

Credentials from Password Stores