Vendor: Microsoft

July 25, 2023 · View on GitHub

Product: Windows Defender

RulesModelsMITRE TTPsEvent TypesParsers
97451166
Use-CaseEvent Types/ParsersMITRE TTPContent
Account Manipulationapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 3 Rules
  • 1 Models
Compromised Credentialsapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1059.001 - Command and Scripting Interperter: PowerShell
T1078 - Valid Accounts
T1133 - External Remote Services
  • 60 Rules
  • 30 Models
Data Accessapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1078 - Valid Accounts
  • 27 Rules
  • 15 Models
Data Exfiltrationapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1020 - Automated Exfiltration
T1048 - Exfiltration Over Alternative Protocol
T1204 - User Execution
  • 15 Rules
  • 9 Models
Data Leakapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1020 - Automated Exfiltration
T1048 - Exfiltration Over Alternative Protocol
T1114.003 - Email Collection: Email Forwarding Rule
T1204 - User Execution
  • 17 Rules
  • 9 Models
Evasionapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1090.003 - Proxy: Multi-hop Proxy
  • 2 Rules
Lateral Movementapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
  • 1 Rules
Malwareapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1204 - User Execution
  • 8 Rules
  • 4 Models
Privilege Abuseapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1078 - Valid Accounts
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 5 Rules
  • 1 Models
Privilege Escalationapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 3 Rules
  • 1 Models
Privileged Activityapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1068 - Exploitation for Privilege Escalation
T1078 - Valid Accounts
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 5 Rules
  • 2 Models
Ransomwareapp-activity
ms-azure-eventhubs-app-activity

app-activity-failed
ms-azure-eventhubs-app-activity

app-login
ms-azure-eventhubs-login

dlp-alert
s-o365-dlp-alert
s-o365-dlp-alert-1

failed-app-login
ms-azure-eventhubs-login

security-alert
microsoft-scep-epp-alert
forefront-epp-cef-alert
raw-scep-epp-alert-csv
raw-scep-alert
json-microsoft-scep-epp-alert
raw-scep-epp-alert
s-scep-epp-alert
microsoft-scep-security-alert
cef-windows-defender
win-def-mal-detect
T1078 - Valid Accounts
  • 2 Rules

ATT&CK Matrix for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Command and Scripting Interperter

User Execution

Command and Scripting Interperter: PowerShell

External Remote Services

Valid Accounts

Account Manipulation

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Exploitation for Privilege Escalation

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Obfuscated Files or Information

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy

Exfiltration Over Alternative Protocol

Automated Exfiltration