Vendor: GTB

July 25, 2023 · View on GitHub

Product: GTBInspector

RulesModelsMITRE TTPsEvent TypesParsers
1911311
Use-CaseEvent Types/ParsersMITRE TTPContent
Data Exfiltrationdlp-alert
cef-gtb-dlp-alert
T1020 - Automated Exfiltration
T1048 - Exfiltration Over Alternative Protocol
T1204 - User Execution
  • 15 Rules
  • 9 Models
Data Leakdlp-alert
cef-gtb-dlp-alert
T1020 - Automated Exfiltration
T1048 - Exfiltration Over Alternative Protocol
T1204 - User Execution
  • 15 Rules
  • 9 Models
Malwaredlp-alert
cef-gtb-dlp-alert
T1204 - User Execution
  • 4 Rules
  • 2 Models

ATT&CK Matrix for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
User Execution

Exfiltration Over Alternative Protocol

Automated Exfiltration