Use Case: Brute Force Attack
June 14, 2023 · View on GitHub
Use Case: Brute Force Attack
Vendor: Accellion
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Kiteworks |
| T1110 - Brute Force |
|
Vendor: Airlock
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Web Application Firewall |
| T1110 - Brute Force |
|
Vendor: Amazon
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| AWS Bastion |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Auth0
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Auth0 |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Barracuda
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Barracuda Firewall |
| T1110 - Brute Force |
|
Vendor: CDS
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| CDS |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: CatoNetworks
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Cato Cloud |
| T1110 - Brute Force |
|
Vendor: Check Point
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Identity Awareness |
| T1110 - Brute Force |
|
| NGFW |
| T1110 - Brute Force |
|
| Security Gateway |
| T1110 - Brute Force |
|
Vendor: Cisco
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Adaptive Security Appliance |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
| AnyConnect |
| T1110 - Brute Force |
|
| Duo Access Security |
| T1110 - Brute Force |
|
| Firepower |
| T1110 - Brute Force |
|
| ISE |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
| Meraki MX appliances |
| T1110 - Brute Force |
|
Vendor: Citrix
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Citrix Netscaler |
| T1110 - Brute Force |
|
| Citrix Netscaler VPN |
| T1110 - Brute Force |
|
Vendor: CyberArk
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| CyberArk Vault |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Delinea
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Centrify Authentication Service |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Dell
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| RSA Authentication Manager |
| T1110 - Brute Force |
|
| SonicWALL Aventail |
| T1110 - Brute Force |
|
Vendor: Dropbox
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Dropbox |
| T1110 - Brute Force |
|
Vendor: ESET
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| ESET Endpoint Security |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Entrust
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| IdentityGuard |
| T1110 - Brute Force |
|
Vendor: Extreme Networks
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Zebra wireless LAN management |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: F5
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| F5 BIG-IP |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
| F5 BIG-IP Access Policy Manager (APM) |
| T1110 - Brute Force |
|
Vendor: Forescout
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| EyeInspect |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Fortinet
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Fortinet VPN |
| T1110 - Brute Force |
|
Vendor: GoAnywhere
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| GoAnywhere MFT |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: IBM
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| IBM Sterling B2B Integrator |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Ipswitch
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| MoveIt DMZ |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Juniper Networks
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Juniper Networks Pulse Secure |
| T1110 - Brute Force |
|
| Juniper VPN |
| T1110 - Brute Force |
|
Vendor: Linux
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| SSH |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Microsoft
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Defender ATP |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
| Routing and Remote Access Service |
| T1110 - Brute Force |
|
| Windows |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: NCP
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| NCP |
| T1110 - Brute Force |
|
Vendor: NetMotion Wireless
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| NetMotion Wireless |
| T1110 - Brute Force |
|
Vendor: Netwrix
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Netwrix Auditor |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Nortel Contivity
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Nortel Contivity VPN |
| T1110 - Brute Force |
|
Vendor: Okta
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Okta Adaptive MFA |
| T1110 - Brute Force |
|
Vendor: OneSpan
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| OneSpan |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Palo Alto Networks
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| GlobalProtect |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Quest Software
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Change Auditor |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: RSA
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| SecurID |
| T1110 - Brute Force |
|
Vendor: SAP
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| SAP |
| T1110 - Brute Force |
|
Vendor: SSL Open VPN
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| SSL Open VPN |
| T1110 - Brute Force |
|
Vendor: Sailpoint
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| SecurityIQ |
| T1110 - Brute Force |
|
Vendor: SecureNet
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| SecureNet |
| T1110 - Brute Force |
|
Vendor: Sonicwall
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Sonicwall |
| T1110 - Brute Force |
|
Vendor: Sophos
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Sophos XG Firewall |
| T1110 - Brute Force |
|
Vendor: Symantec
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Symantec Critical System Protection |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Unix
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Unix |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
| Unix Auditd |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: VMS Software
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| OpenVMS |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: VMware
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| VMware VCenter |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Zeek
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Zeek Network Security Monitor |
| T1021.001 - Remote Services: Remote Desktop Protocol T1110 - Brute Force T1110.003 - T1110.003 |
|
Vendor: Zscaler
| Product | Event Types | MITRE ATT&CK® TTP | Content |
|---|---|---|---|
| Zscaler Private Access |
| T1110 - Brute Force |
|