Vendor: Dell

July 25, 2023 · View on GitHub

Product: Dell EMC Isilon

RulesModelsMITRE TTPsEvent TypesParsers
55271344
Use-CaseEvent Types/ParsersMITRE TTPContent
Brute Force Attackfile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1078 - Valid Accounts
  • 1 Rules
  • 1 Models
Compromised Credentialsfile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1003.003 - T1003.003
T1021 - Remote Services
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 18 Rules
  • 9 Models
Data Accessfile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1083 - File and Directory Discovery
  • 3 Rules
  • 3 Models
Data Exfiltrationfile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1204 - User Execution
  • 2 Rules
  • 1 Models
Lateral Movementfile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1018 - Remote System Discovery
T1021 - Remote Services
T1078 - Valid Accounts
T1550 - Use Alternate Authentication Material
T1550.002 - Use Alternate Authentication Material: Pass the Hash
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
  • 31 Rules
  • 17 Models
Malwarefile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1085 - Signed Binary Proxy Execution: Rundll32
T1204 - User Execution
  • 8 Rules
  • 3 Models
Privilege Abusefile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1021 - Remote Services
T1078 - Valid Accounts
  • 3 Rules
  • 1 Models
Privilege Escalationfile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1078 - Valid Accounts
  • 2 Rules
  • 1 Models
Privileged Activityfile-delete
dell-file-operations-2

file-read
dell-file-operations-1
dell-file-operations-4

file-write
dell-file-operations-3
json-dell-file-operations

remote-access
dell-file-remote-access
T1021 - Remote Services
T1068 - Exploitation for Privilege Escalation
T1078 - Valid Accounts
  • 3 Rules
  • 1 Models

ATT&CK Matrix for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

User Execution

Valid Accounts

Valid Accounts

Exploitation for Privilege Escalation

Signed Binary Proxy Execution: Rundll32

Valid Accounts

Use Alternate Authentication Material

Use Alternate Authentication Material: Pass the Hash

Obfuscated Files or Information

OS Credential Dumping

Steal or Forge Kerberos Tickets

Steal or Forge Kerberos Tickets: Kerberoasting

File and Directory Discovery

Remote System Discovery

Remote Services

Use Alternate Authentication Material