Vendor: Sangfor
July 25, 2023 · View on GitHub
Product: NGAF
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 67 | 26 | 12 | 3 | 3 |
| Use-Case | Event Types/Parsers | MITRE TTP | Content |
|---|---|---|---|
| Compromised Credentials | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools T1071.001 - Application Layer Protocol: Web Protocols T1102 - Web Service T1550.002 - Use Alternate Authentication Material: Pass the Hash |
|
| Cryptomining | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1071.001 - Application Layer Protocol: Web Protocols T1496 - Resource Hijacking |
|
| Data Exfiltration | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1030 - Data Transfer Size Limits T1071.001 - Application Layer Protocol: Web Protocols T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage T1568 - Dynamic Resolution |
|
| Data Leak | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1030 - Data Transfer Size Limits T1071.001 - Application Layer Protocol: Web Protocols T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage |
|
| Evasion | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1071.001 - Application Layer Protocol: Web Protocols T1090.003 - Proxy: Multi-hop Proxy |
|
| Lateral Movement | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Malware | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Phishing | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Privileged Activity | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1071.001 - Application Layer Protocol: Web Protocols T1102 - Web Service |
|
| Ransomware | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1071 - Application Layer Protocol |
|
| Workforce Protection | network-alert ↳ sangfor-network-alert web-activity-allowed ↳ sangfor-web-activity web-activity-denied ↳ sangfor-web-activity | T1071.001 - Application Layer Protocol: Web Protocols |
|
ATT&CK Matrix for Enterprise
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Phishing: Spearphishing Link Phishing | User Execution | Obfuscated Files or Information: Indicator Removal from Tools Use Alternate Authentication Material Use Alternate Authentication Material: Pass the Hash Obfuscated Files or Information | Use Alternate Authentication Material | Web Service Application Layer Protocol: Web Protocols Dynamic Resolution Dynamic Resolution: Domain Generation Algorithms Proxy: Multi-hop Proxy Application Layer Protocol Proxy | Data Transfer Size Limits Exfiltration Over Web Service: Exfiltration to Cloud Storage Exfiltration Over Web Service | Resource Hijacking |