Vendor: Cisco

July 25, 2023 · View on GitHub

Product: AnyConnect

Use-Case: Phishing

RulesModelsMITRE TTPsEvent TypesParsers
22133
Event TypeRulesModels
vpn-logoutT1566 - Phishing
EM-FNum-in: Abnormal number of incoming emails
EM-BSum-in: Abnormal size of incoming emails
EM-BSum-in: Sum of bytes in incoming emails
EM-FNum-in: Count of incoming emails