2_ds_unix_unix_sendmail.md
June 14, 2023 · View on GitHub
| Use-Case | Event Types/Parsers | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Privilege Abuse | dlp-email-alert-in ↳q-sendmail-dlp-email-alert ↳sendmail-email-from ↳s-sendmail-email-from dlp-email-alert-in-failed ↳sendmail-email-from ↳s-sendmail-email-from dlp-email-alert-out ↳q-sendmail-dlp-email-alert ↳sendmail-email-from ↳s-sendmail-email-from dlp-email-alert-out-failed ↳sendmail-email-from ↳s-sendmail-email-from | T1078 - Valid Accounts |
|
| Privileged Activity | dlp-email-alert-in ↳q-sendmail-dlp-email-alert ↳sendmail-email-from ↳s-sendmail-email-from dlp-email-alert-in-failed ↳sendmail-email-from ↳s-sendmail-email-from dlp-email-alert-out ↳q-sendmail-dlp-email-alert ↳sendmail-email-from ↳s-sendmail-email-from dlp-email-alert-out-failed ↳sendmail-email-from ↳s-sendmail-email-from | T1078 - Valid Accounts |
|