Vendor: FireEye

July 25, 2023 · View on GitHub

Product: FireEye Helix

RulesModelsMITRE TTPsEvent TypesParsers
96211
Use-CaseEvent Types/ParsersMITRE TTPContent
Compromised Credentialsnetwork-alert
json-fireeye-alert-network
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
  • 5 Rules
  • 4 Models
Malwarenetwork-alert
json-fireeye-alert-network
T1204 - User Execution
  • 4 Rules
  • 2 Models

ATT&CK Matrix for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
User Execution

Obfuscated Files or Information: Indicator Removal from Tools

Obfuscated Files or Information