Vendor: CatoNetworks
July 25, 2023 · View on GitHub
Product: Cato Cloud
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 103 | 53 | 23 | 6 | 6 |
| Use-Case | Event Types/Parsers | MITRE TTP | Content |
|---|---|---|---|
| Account Manipulation | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Brute Force Attack | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1003 - OS Credential Dumping |
|
| Compromised Credentials | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1102 - Web Service T1110 - Brute Force T1133 - External Remote Services T1550.002 - Use Alternate Authentication Material: Pass the Hash |
|
| Cryptomining | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1071.001 - Application Layer Protocol: Web Protocols T1496 - Resource Hijacking |
|
| Data Access | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1078 - Valid Accounts T1110 - Brute Force |
|
| Data Exfiltration | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1030 - Data Transfer Size Limits T1071.001 - Application Layer Protocol: Web Protocols T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage T1568 - Dynamic Resolution |
|
| Data Leak | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1030 - Data Transfer Size Limits T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1052 - Exfiltration Over Physical Medium T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB T1071.001 - Application Layer Protocol: Web Protocols T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage |
|
| Evasion | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1071.001 - Application Layer Protocol: Web Protocols T1090.003 - Proxy: Multi-hop Proxy |
|
| Lateral Movement | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting |
|
| Malware | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Phishing | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
| Privilege Abuse | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Privilege Escalation | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1003 - OS Credential Dumping T1098.002 - Account Manipulation: Exchange Email Delegate Permissions |
|
| Privileged Activity | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1102 - Web Service |
|
| Ransomware | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1071 - Application Layer Protocol T1078 - Valid Accounts |
|
| Workforce Protection | network-alert ↳ cef-catonetworks-network-alert vpn-connection ↳ cef-catonetworks-web-activity vpn-login ↳ cef-catonetworks-vpn-login vpn-logout ↳ cef-catonetworks-vpn-end web-activity-allowed ↳ cef-catonetworks-web-activity web-activity-denied ↳ cef-catonetworks-web-activity | T1071.001 - Application Layer Protocol: Web Protocols |
|