Use Case: Brute Force Attack

June 14, 2023 · View on GitHub

Use Case: Brute Force Attack

Vendor: Accellion

ProductEvent TypesMITRE ATT&CK® TTPContent
Kiteworks
  • account-lockout
  • account-password-change
  • account-password-reset
  • account-unlocked
  • app-activity
  • app-login
  • dlp-alert
  • dlp-email-alert-out
  • failed-app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
T1110 - Brute Force
  • 1 Rules

Vendor: Airlock

ProductEvent TypesMITRE ATT&CK® TTPContent
Web Application Firewall
  • app-activity-failed
  • app-login
  • failed-app-login
  • file-delete
  • file-download
  • file-upload
  • file-write
  • network-connection-failed
  • network-connection-successful
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Amazon

ProductEvent TypesMITRE ATT&CK® TTPContent
AWS Bastion
  • failed-logon
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Auth0

ProductEvent TypesMITRE ATT&CK® TTPContent
Auth0
  • account-password-change-failed
  • app-login
  • failed-logon
  • security-alert
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Barracuda

ProductEvent TypesMITRE ATT&CK® TTPContent
Barracuda Firewall
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • remote-logon
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: CDS

ProductEvent TypesMITRE ATT&CK® TTPContent
CDS
  • failed-logon
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: CatoNetworks

ProductEvent TypesMITRE ATT&CK® TTPContent
Cato Cloud
  • network-alert
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Check Point

ProductEvent TypesMITRE ATT&CK® TTPContent
Identity Awareness
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models
NGFW
  • app-login
  • authentication-failed
  • authentication-successful
  • dlp-email-alert-in
  • dlp-email-alert-out
  • failed-vpn-login
  • local-logon
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1110 - Brute Force
  • 1 Rules
  • 1 Models
Security Gateway
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Cisco

ProductEvent TypesMITRE ATT&CK® TTPContent
Adaptive Security Appliance
  • authentication-failed
  • authentication-successful
  • dns-response
  • failed-logon
  • failed-vpn-login
  • file-download
  • file-upload
  • nac-logon
  • network-connection-successful
  • process-created
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-denied
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 10 Rules
  • 1 Models
AnyConnect
  • process-network
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models
Duo Access Security
  • account-creation
  • account-deleted
  • account-lockout
  • account-password-reset
  • app-activity
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • failed-vpn-login
  • vpn-login
T1110 - Brute Force
  • 1 Rules
Firepower
  • authentication-successful
  • dns-query
  • dns-response
  • failed-vpn-login
  • file-download
  • nac-logon
  • netflow-connection
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • process-created
  • security-alert
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1110 - Brute Force
  • 1 Rules
  • 1 Models
ISE
  • app-activity
  • authentication-failed
  • authentication-successful
  • computer-logon
  • config-change
  • failed-logon
  • failed-vpn-login
  • nac-failed-logon
  • nac-logon
  • remote-logon
  • vpn-login
  • vpn-logout
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 10 Rules
  • 1 Models
Meraki MX appliances
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Citrix

ProductEvent TypesMITRE ATT&CK® TTPContent
Citrix Netscaler
  • app-login
  • authentication-failed
  • failed-vpn-login
  • process-created
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models
Citrix Netscaler VPN
  • authentication-failed
  • authentication-successful
  • remote-access
  • remote-logon
  • vpn-connection
  • vpn-logout
  • web-activity-allowed
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: CyberArk

ProductEvent TypesMITRE ATT&CK® TTPContent
CyberArk Vault
  • account-password-change
  • account-password-change-failed
  • account-password-reset
  • account-switch
  • app-activity
  • app-activity-failed
  • app-login
  • failed-app-login
  • failed-logon
  • file-delete
  • file-permission-change
  • file-read
  • file-write
  • remote-logon
  • security-alert
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Delinea

ProductEvent TypesMITRE ATT&CK® TTPContent
Centrify Authentication Service
  • account-password-reset
  • authentication-failed
  • authentication-successful
  • failed-logon
  • local-logon
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Dell

ProductEvent TypesMITRE ATT&CK® TTPContent
RSA Authentication Manager
  • account-lockout
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-app-login
T1110 - Brute Force
  • 1 Rules
SonicWALL Aventail
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Dropbox

ProductEvent TypesMITRE ATT&CK® TTPContent
Dropbox
  • app-activity
  • app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-write
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: ESET

ProductEvent TypesMITRE ATT&CK® TTPContent
ESET Endpoint Security
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-logon
  • network-alert
  • security-alert
  • web-activity-denied
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Entrust

ProductEvent TypesMITRE ATT&CK® TTPContent
IdentityGuard
  • account-lockout
  • authentication-failed
  • authentication-successful
T1110 - Brute Force
  • 1 Rules

Vendor: Extreme Networks

ProductEvent TypesMITRE ATT&CK® TTPContent
Zebra wireless LAN management
  • failed-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: F5

ProductEvent TypesMITRE ATT&CK® TTPContent
F5 BIG-IP
  • account-password-change-failed
  • authentication-failed
  • authentication-successful
  • failed-logon
  • failed-vpn-login
  • network-connection-successful
  • remote-logon
  • vpn-login
  • vpn-logout
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 10 Rules
  • 1 Models
F5 BIG-IP Access Policy Manager (APM)
  • authentication-failed
  • authentication-successful
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Forescout

ProductEvent TypesMITRE ATT&CK® TTPContent
EyeInspect
  • failed-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Fortinet

ProductEvent TypesMITRE ATT&CK® TTPContent
Fortinet VPN
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: GoAnywhere

ProductEvent TypesMITRE ATT&CK® TTPContent
GoAnywhere MFT
  • failed-logon
  • file-delete
  • file-download
  • file-upload
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: IBM

ProductEvent TypesMITRE ATT&CK® TTPContent
IBM Sterling B2B Integrator
  • app-activity
  • failed-logon
  • member-added
  • member-removed
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Ipswitch

ProductEvent TypesMITRE ATT&CK® TTPContent
MoveIt DMZ
  • account-password-change
  • authentication-failed
  • authentication-successful
  • failed-logon
  • file-delete
  • file-download
  • file-upload
  • file-write
  • member-added
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Juniper Networks

ProductEvent TypesMITRE ATT&CK® TTPContent
Juniper Networks Pulse Secure
  • account-deleted
  • app-activity
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • network-connection-failed
  • vpn-connection
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models
Juniper VPN
  • account-deleted
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
  • web-activity-allowed
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Linux

ProductEvent TypesMITRE ATT&CK® TTPContent
SSH
  • failed-logon
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Microsoft

ProductEvent TypesMITRE ATT&CK® TTPContent
Defender ATP
  • app-login
  • batch-logon
  • failed-logon
  • file-delete
  • file-write
  • local-logon
  • member-added
  • member-removed
  • process-created
  • process-network
  • process-network-failed
  • remote-access
  • remote-logon
  • security-alert
  • service-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules
Routing and Remote Access Service
  • authentication-successful
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models
Windows
  • account-creation
  • account-deleted
  • account-disabled
  • account-enabled
  • account-lockout
  • account-password-change
  • account-password-change-failed
  • account-password-reset
  • account-switch
  • account-unlocked
  • app-login
  • audit-log-clear
  • audit-policy-change
  • authentication-failed
  • authentication-successful
  • batch-logon
  • computer-logon
  • config-change
  • dcom-activation-failed
  • dns-query
  • dns-response
  • ds-access
  • failed-app-login
  • failed-logon
  • failed-vpn-login
  • file-close
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • local-logon
  • logout-remote
  • member-added
  • member-removed
  • nac-failed-logon
  • nac-logon
  • network-connection-successful
  • ntlm-logon
  • privileged-access
  • privileged-object-access
  • process-created
  • process-network
  • process-network-failed
  • registry-write
  • remote-access
  • remote-logon
  • security-alert
  • service-created
  • service-logon
  • share-access
  • share-access-denied
  • task-created
  • usb-activity
  • usb-insert
  • vpn-login
  • vpn-logout
  • winsession-disconnect
  • workstation-locked
  • workstation-unlocked
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 11 Rules
  • 1 Models

Vendor: NCP

ProductEvent TypesMITRE ATT&CK® TTPContent
NCP
  • authentication-failed
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: NetMotion Wireless

ProductEvent TypesMITRE ATT&CK® TTPContent
NetMotion Wireless
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Netwrix

ProductEvent TypesMITRE ATT&CK® TTPContent
Netwrix Auditor
  • account-disabled
  • account-lockout
  • account-password-reset
  • account-unlocked
  • app-activity
  • app-login
  • database-access
  • database-failed-login
  • ds-access
  • failed-app-login
  • failed-logon
  • file-delete
  • file-write
  • member-added
  • member-removed
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 10 Rules

Vendor: Nortel Contivity

ProductEvent TypesMITRE ATT&CK® TTPContent
Nortel Contivity VPN
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Okta

ProductEvent TypesMITRE ATT&CK® TTPContent
Okta Adaptive MFA
  • account-creation
  • account-enabled
  • account-lockout
  • account-password-change
  • account-password-reset
  • app-activity
  • app-activity-failed
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • member-added
  • member-removed
  • security-alert
T1110 - Brute Force
  • 1 Rules

Vendor: OneSpan

ProductEvent TypesMITRE ATT&CK® TTPContent
OneSpan
  • failed-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Palo Alto Networks

ProductEvent TypesMITRE ATT&CK® TTPContent
GlobalProtect
  • app-activity
  • authentication-failed
  • authentication-successful
  • config-change
  • failed-logon
  • failed-vpn-login
  • remote-logon
  • vpn-login
  • vpn-logout
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 10 Rules
  • 1 Models

Vendor: Quest Software

ProductEvent TypesMITRE ATT&CK® TTPContent
Change Auditor
  • account-lockout
  • account-password-change
  • account-password-change-failed
  • account-unlocked
  • ds-access
  • failed-ds-access
  • failed-logon
  • file-delete
  • file-read
  • file-write
  • local-logon
  • member-added
  • member-removed
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 10 Rules

Vendor: RSA

ProductEvent TypesMITRE ATT&CK® TTPContent
SecurID
  • authentication-failed
  • authentication-successful
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: SAP

ProductEvent TypesMITRE ATT&CK® TTPContent
SAP
  • account-creation
  • account-deleted
  • account-lockout
  • account-password-change
  • account-unlocked
  • app-activity
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • file-download
  • file-write
  • gcp-bucket-create
  • gcp-compute-list
  • gcp-function-write
  • gcp-general-activity
  • gcp-instance-screenshot
  • gcp-role-list
  • gcp-serviceaccount-creds-write
  • gcp-storage-list
  • gcp-storageobject-read
  • gcp-storageobject-write
  • remote-logon
T1110 - Brute Force
  • 1 Rules

Vendor: SSL Open VPN

ProductEvent TypesMITRE ATT&CK® TTPContent
SSL Open VPN
  • app-activity
  • app-activity-failed
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Sailpoint

ProductEvent TypesMITRE ATT&CK® TTPContent
SecurityIQ
  • account-creation
  • account-deleted
  • account-lockout
  • account-password-reset
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • member-added
  • member-removed
T1110 - Brute Force
  • 1 Rules

Vendor: SecureNet

ProductEvent TypesMITRE ATT&CK® TTPContent
SecureNet
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Sonicwall

ProductEvent TypesMITRE ATT&CK® TTPContent
Sonicwall
  • failed-vpn-login
  • network-alert
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Sophos

ProductEvent TypesMITRE ATT&CK® TTPContent
Sophos XG Firewall
  • app-login
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Symantec

ProductEvent TypesMITRE ATT&CK® TTPContent
Symantec Critical System Protection
  • account-switch
  • config-change
  • failed-logon
  • local-logon
  • member-added
  • member-removed
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Unix

ProductEvent TypesMITRE ATT&CK® TTPContent
Unix
  • account-creation
  • account-deleted
  • account-lockout
  • account-password-change
  • account-switch
  • authentication-failed
  • authentication-successful
  • batch-logon
  • computer-logon
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-logon
  • file-delete
  • file-permission-change
  • file-read
  • file-write
  • kerberos-logon
  • local-logon
  • member-added
  • member-removed
  • network-connection-failed
  • process-created
  • process-created-failed
  • remote-access
  • remote-logon
  • security-alert
  • task-created
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 10 Rules
Unix Auditd
  • account-creation
  • account-deleted
  • account-password-change
  • account-switch
  • app-activity-failed
  • authentication-failed
  • authentication-successful
  • failed-logon
  • local-logon
  • member-added
  • member-removed
  • process-created
  • process-created-failed
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: VMS Software

ProductEvent TypesMITRE ATT&CK® TTPContent
OpenVMS
  • batch-logon
  • failed-logon
  • file-delete
  • file-read
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: VMware

ProductEvent TypesMITRE ATT&CK® TTPContent
VMware VCenter
  • app-activity
  • app-login
  • failed-logon
  • remote-logon
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Zeek

ProductEvent TypesMITRE ATT&CK® TTPContent
Zeek Network Security Monitor
  • app-activity
  • authentication-failed
  • authentication-successful
  • computer-logon
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dns-query
  • dns-response
  • failed-logon
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • nac-failed-logon
  • nac-logon
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • ntlm-logon
  • remote-access
  • remote-logon
  • share-access
  • web-activity-allowed
  • web-activity-denied
T1021.001 - Remote Services: Remote Desktop Protocol
T1110 - Brute Force
T1110.003 - T1110.003
  • 9 Rules

Vendor: Zscaler

ProductEvent TypesMITRE ATT&CK® TTPContent
Zscaler Private Access
  • vpn-login
  • vpn-logout
T1110 - Brute Force
  • 1 Rules
  • 1 Models