Vendor: VMware

June 30, 2023 · View on GitHub

Product: AirWatch

Use-Case: Lateral Movement

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
60344
Event TypeRulesModels
app-activityT1090.003 - Proxy: Multi-hop Proxy
Auth-Tor-Shost: User authentication or login from a known TOR IP
authentication-failedT1078 - Valid Accounts
Auth-Tor-Shost-Failed: User authentication or login failure from a known TOR IP

T1090.003 - Proxy: Multi-hop Proxy
Auth-Tor-Shost-Failed: User authentication or login failure from a known TOR IP
authentication-successfulT1090.003 - Proxy: Multi-hop Proxy
Auth-Tor-Shost: User authentication or login from a known TOR IP
security-alertT1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
A-ALERT-DL: DL Correlation rule alert on asset
A-ALERT-Correlation-Rule: Correlation rule alert on asset
ALERT-Correlation-Rule: Correlation rule alert on asset accessed by this user
ALERT-DL: DL Correlation rule alert on asset accessed by this user