| Brute Force Attack | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1021.001 - Remote Services: Remote Desktop Protocol T1078 - Valid Accounts T1110 - Brute Force
| |
| Compromised Credentials | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1021 - Remote Services T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1078.003 - Valid Accounts: Local Accounts T1102 - Web Service T1110 - Brute Force T1133 - External Remote Services T1550.002 - Use Alternate Authentication Material: Pass the Hash
| |
| Cryptomining | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1071.001 - Application Layer Protocol: Web Protocols T1496 - Resource Hijacking
| |
| Data Exfiltration | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1030 - Data Transfer Size Limits T1071.001 - Application Layer Protocol: Web Protocols T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage T1568 - Dynamic Resolution
| |
| Data Leak | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1030 - Data Transfer Size Limits T1071.001 - Application Layer Protocol: Web Protocols T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage
| |
| Evasion | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1071.001 - Application Layer Protocol: Web Protocols T1090.003 - Proxy: Multi-hop Proxy
| |
| Lateral Movement | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1018 - Remote System Discovery T1021 - Remote Services T1021.001 - Remote Services: Remote Desktop Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1078.003 - Valid Accounts: Local Accounts T1090.002 - Proxy: External Proxy T1110 - Brute Force T1550 - Use Alternate Authentication Material T1550.002 - Use Alternate Authentication Material: Pass the Hash T1550.003 - Use Alternate Authentication Material: Pass the Ticket T1550.004 - Use Alternate Authentication Material: Web Session Cookie T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1571 - Non-Standard Port
| |
| Malware | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms
| |
| Phishing | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link
| |
| Privilege Abuse | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1078 - Valid Accounts
| |
| Privilege Escalation | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1078 - Valid Accounts T1210 - Exploitation of Remote Services
| |
| Privileged Activity | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1068 - Exploitation for Privilege Escalation T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1102 - Web Service
| |
| Ransomware | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1071 - Application Layer Protocol T1078 - Valid Accounts
| |
| Workforce Protection | config-change ↳ cise-config-change ↳ cise-config-change-1
dns-query ↳ cef-cisco-firepower-dns-query
dns-response ↳ q-cisco-dns-response ↳ cisco-dns-response-1 ↳ cef-cisco-dns-response-1 ↳ cef-cisco-dns-response-sk4 ↳ cef-cisco-dns-response ↳ cl-cisco-dns-response-sk4-4 ↳ cef-cisco-dns-response-sk4-2 ↳ cef-cisco-dns-response-sk4-3 ↳ cef-cisco-dns-response-sk4-4
failed-logon ↳ cise-remote-logon-2
network-connection-failed ↳ cef-cisco-firepower
network-connection-successful ↳ cef-cisco-firepower
remote-logon ↳ cise-remote-logon ↳ cise-remote-logon-3 ↳ cise-remote-logon-1 ↳ cise-remote-logon-2
web-activity-allowed ↳ cisco-umbrella-intelligent-proxy
web-activity-denied ↳ cisco-umbrella-intelligent-proxy
| T1071.001 - Application Layer Protocol: Web Protocols
| |