Vendor: Vormetric

June 14, 2023 · View on GitHub

Product: Vormetric

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
3416522
Use-CaseEvent Types/ParsersMITRE ATT&CK® TTPContent
Compromised Credentialsfile-read
vormetric-file-operations
T1003.001 - T1003.001
T1003.003 - T1003.003
T1083 - File and Directory Discovery
  • 29 Rules
  • 14 Models
Data Accessfile-read
vormetric-file-operations
T1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models
Data Exfiltrationfile-alert
vormetric-file-operations
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Malwarefile-alert
vormetric-file-operations
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Privilege Abusefile-alert
vormetric-file-operations

file-read
vormetric-file-operations
T1078 - Valid Accounts
  • 1 Rules
Privileged Activityfile-alert
vormetric-file-operations

file-read
vormetric-file-operations
T1078 - Valid Accounts
  • 1 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Valid Accounts

Valid Accounts

Valid Accounts

OS Credential Dumping

File and Directory Discovery