Vendor: BeyondTrust

July 25, 2023 · View on GitHub

Product: BeyondTrust PasswordSafe

RulesModelsMITRE TTPsEvent TypesParsers
107422
Use-CaseEvent Types/ParsersMITRE TTPContent
Brute Force Attackaccount-switch
beyondtrust-passwordsafe

privileged-access
beyondtrust-passwordsafe
T1003 - OS Credential Dumping
T1078 - Valid Accounts
T1098 - Account Manipulation
  • 5 Rules
  • 4 Models
Compromised Credentialsaccount-switch
beyondtrust-passwordsafe

privileged-access
beyondtrust-passwordsafe
T1078 - Valid Accounts
  • 1 Rules
  • 1 Models
Malwareaccount-switch
beyondtrust-passwordsafe

privileged-access
beyondtrust-passwordsafe
T1204 - User Execution
  • 4 Rules
  • 2 Models
Privilege Escalationaccount-switch
beyondtrust-passwordsafe

privileged-access
beyondtrust-passwordsafe
T1003 - OS Credential Dumping
T1078 - Valid Accounts
T1098 - Account Manipulation
  • 5 Rules
  • 4 Models

ATT&CK Matrix for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

User Execution

Valid Accounts

Account Manipulation

Valid Accounts

Valid Accounts

OS Credential Dumping