Vendor: Fidelis

July 25, 2023 · View on GitHub

Product: Fidelis XPS

RulesModelsMITRE TTPsEvent TypesParsers
5926833
Use-CaseEvent Types/ParsersMITRE TTPContent
Compromised Credentialsdlp-email-alert-in
fidelis-email-alert

dlp-email-alert-out
fidelis-email-alert

security-alert
n-forwarded-cef-fidelis-alert
fidelis-leef-alert
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1059.001 - Command and Scripting Interperter: PowerShell
T1078 - Valid Accounts
  • 18 Rules
  • 8 Models
Data Leakdlp-email-alert-in
fidelis-email-alert

dlp-email-alert-out
fidelis-email-alert

security-alert
n-forwarded-cef-fidelis-alert
fidelis-leef-alert
T1020 - Automated Exfiltration
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 29 Rules
  • 14 Models
Lateral Movementdlp-email-alert-in
fidelis-email-alert

dlp-email-alert-out
fidelis-email-alert

security-alert
n-forwarded-cef-fidelis-alert
fidelis-leef-alert
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
  • 1 Rules
Malwaredlp-email-alert-in
fidelis-email-alert

dlp-email-alert-out
fidelis-email-alert

security-alert
n-forwarded-cef-fidelis-alert
fidelis-leef-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 6 Rules
  • 4 Models
Phishingdlp-email-alert-in
fidelis-email-alert

dlp-email-alert-out
fidelis-email-alert

security-alert
n-forwarded-cef-fidelis-alert
fidelis-leef-alert
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Privilege Abusedlp-email-alert-in
fidelis-email-alert

dlp-email-alert-out
fidelis-email-alert

security-alert
n-forwarded-cef-fidelis-alert
fidelis-leef-alert
T1078 - Valid Accounts
  • 1 Rules
Privileged Activitydlp-email-alert-in
fidelis-email-alert

dlp-email-alert-out
fidelis-email-alert

security-alert
n-forwarded-cef-fidelis-alert
fidelis-leef-alert
T1068 - Exploitation for Privilege Escalation
T1078 - Valid Accounts
  • 2 Rules
Workforce Protectiondlp-email-alert-in
fidelis-email-alert

dlp-email-alert-out
fidelis-email-alert

security-alert
n-forwarded-cef-fidelis-alert
fidelis-leef-alert
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 4 Rules
  • 1 Models

ATT&CK Matrix for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Command and Scripting Interperter

User Execution

Command and Scripting Interperter: PowerShell

Valid Accounts

Valid Accounts

Exploitation for Privilege Escalation

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Obfuscated Files or Information

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol

Automated Exfiltration