2_ds_unix_unix_sendmail.md

June 14, 2023 · View on GitHub

Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Privilege Abusedlp-email-alert-in
q-sendmail-dlp-email-alert
sendmail-email-from
s-sendmail-email-from

dlp-email-alert-in-failed
sendmail-email-from
s-sendmail-email-from

dlp-email-alert-out
q-sendmail-dlp-email-alert
sendmail-email-from
s-sendmail-email-from

dlp-email-alert-out-failed
sendmail-email-from
s-sendmail-email-from
T1078 - Valid Accounts
  • 1 Rules
Privileged Activitydlp-email-alert-in
q-sendmail-dlp-email-alert
sendmail-email-from
s-sendmail-email-from

dlp-email-alert-in-failed
sendmail-email-from
s-sendmail-email-from

dlp-email-alert-out
q-sendmail-dlp-email-alert
sendmail-email-from
s-sendmail-email-from

dlp-email-alert-out-failed
sendmail-email-from
s-sendmail-email-from
T1078 - Valid Accounts
  • 1 Rules