Vendor: McAfee

July 25, 2023 · View on GitHub

Product: McAfee Endpoint Security

RulesModelsMITRE TTPsEvent TypesParsers
13263271111
Use-CaseEvent Types/ParsersMITRE TTPContent
Brute Force Attackdlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1078 - Valid Accounts
  • 1 Rules
  • 1 Models
Compromised Credentialsdlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1003.003 - T1003.003
T1021 - Remote Services
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1059.001 - Command and Scripting Interperter: PowerShell
T1078 - Valid Accounts
T1078.003 - Valid Accounts: Local Accounts
T1083 - File and Directory Discovery
T1133 - External Remote Services
  • 49 Rules
  • 25 Models
Data Accessdlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 4 Rules
  • 3 Models
Data Exfiltrationdlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1020 - Automated Exfiltration
T1048 - Exfiltration Over Alternative Protocol
T1204 - User Execution
  • 17 Rules
  • 10 Models
Data Leakdlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1020 - Automated Exfiltration
T1048 - Exfiltration Over Alternative Protocol
T1052 - Exfiltration Over Physical Medium
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
T1204 - User Execution
  • 22 Rules
  • 12 Models
Evasiondlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1090.003 - Proxy: Multi-hop Proxy
  • 1 Rules
Lateral Movementdlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1018 - Remote System Discovery
T1021 - Remote Services
T1021.003 - T1021.003
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1078 - Valid Accounts
T1078.003 - Valid Accounts: Local Accounts
T1550 - Use Alternate Authentication Material
T1550.002 - Use Alternate Authentication Material: Pass the Hash
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
  • 38 Rules
  • 21 Models
Malwaredlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1078 - Valid Accounts
T1085 - Signed Binary Proxy Execution: Rundll32
T1090.003 - Proxy: Multi-hop Proxy
T1117 - T1117
T1118 - T1118
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1170 - T1170
T1204 - User Execution
T1220 - XSL Script Processing
  • 23 Rules
  • 10 Models
Privilege Abusedlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1078 - Valid Accounts
  • 5 Rules
  • 2 Models
Privilege Escalationdlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1078 - Valid Accounts
  • 2 Rules
  • 1 Models
Privileged Activitydlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1068 - Exploitation for Privilege Escalation
T1078 - Valid Accounts
  • 5 Rules
  • 2 Models
Ransomwaredlp-alert
s-mcafee-epo-dlp-alert-2
mcafee-dlp-upload

failed-app-login
cef-mcafee-skyhigh-failed-app-login

file-write
mcafee-file-write-denied

print-activity
mcafee-dlp-print-2
mcafee-dlp-print

process-alert
s-mcafee-process-alert
cef-mcafee-process-alert

process-created-failed
mcafee-process-created-failed

remote-logon
mcafee-remote-logon

security-alert
s-mcafee-cleaned-alert
n-forwarded-cef-mcafee-epo
s-mcafee-deleted-alert
s-mcafee-epo-alert
s-mcafee-clean-failed-alert
s-mcafee-epo-alert-3
s-mcafee-epo-alert-2
cef-mcafee-security-alert
cef-mcafee-security-alert-1
mcafee-epp-alert
q-mcafee-epo-alert
mcafee-vse-epo-alert
syslog-mcafee-epo-alert
u-mcafee-epo-alert
json-mcafee-epo-alert
cef-mcafee-epo-alert-1
json-mcafee-epo-alert-1
cef-mcafee-vse-alert
s-mcafee-security-alert
s-mcafee-security-alert-1
cef-mcafee-epo-alert-3
mcafee-security-alert-1
cef-mcafee-epo-alert-4
cef-mcafee-epo-alert-5
s-mcafee-security-alert-2
cef-mcafee-epo-alert-6
mcafee-security-alert-4
cef-mcafee-epo-alert-2

usb-activity
mcafee-usb-activity
mcafee-usb-activity-1

usb-insert
cef-mcafee-usb-insert
mcafee-usb-insert
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
mcafee-usb-insert-1

usb-write
mcafee-usb-write
s-mcafee-usb-filewrite
s-mcafee-usb-activity
syslog-mcafee-usb-activity
cef-mcafee-usb-activity-1
s-mcafee-usb-activity-bluetooth
n-forwarded-cef-mcafee-epo-usb
s-mcafee-usb-activity-portable
s-mcafee-usb-activity-dvd
s-mcafee-usb-activity-imaging
s-mcafee-usb-activity-diskdrives
cef-mcafee-usb-activity
mcafee-dlp-rem-stor
mcafee-dlp-pnp
mcafee-dlp-pnp-2
mcafee-dlp-rem-stor-2
mcafee-dlp-mem-dev
T1078 - Valid Accounts
  • 1 Rules

ATT&CK Matrix for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Command and Scripting Interperter

User Execution

Command and Scripting Interperter: PowerShell

External Remote Services

Valid Accounts

Valid Accounts

Exploitation for Privilege Escalation

Signed Binary Proxy Execution: Rundll32

Trusted Developer Utilities Proxy Execution

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Use Alternate Authentication Material

Use Alternate Authentication Material: Pass the Hash

XSL Script Processing

Obfuscated Files or Information

Valid Accounts: Local Accounts

Trusted Developer Utilities Proxy Execution: MSBuild

OS Credential Dumping

Steal or Forge Kerberos Tickets

Steal or Forge Kerberos Tickets: Kerberoasting

File and Directory Discovery

Remote System Discovery

Remote Services

Use Alternate Authentication Material

Proxy: Multi-hop Proxy

Proxy

Exfiltration Over Alternative Protocol

Exfiltration Over Physical Medium: Exfiltration over USB

Exfiltration Over Physical Medium

Automated Exfiltration