| Compromised Credentials | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071.001 - Application Layer Protocol: Web Protocols T1102 - Web Service T1550.002 - Use Alternate Authentication Material: Pass the Hash
| |
| Cryptomining | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071.001 - Application Layer Protocol: Web Protocols T1496 - Resource Hijacking
| |
| Data Exfiltration | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1030 - Data Transfer Size Limits T1071.001 - Application Layer Protocol: Web Protocols T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage T1568 - Dynamic Resolution
| |
| Data Leak | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1030 - Data Transfer Size Limits T1071.001 - Application Layer Protocol: Web Protocols T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage
| |
| Evasion | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071.001 - Application Layer Protocol: Web Protocols T1090.003 - Proxy: Multi-hop Proxy
| |
| Lateral Movement | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols
| |
| Malware | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms
| |
| Phishing | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link
| |
| Privileged Activity | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071.001 - Application Layer Protocol: Web Protocols T1102 - Web Service
| |
| Ransomware | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071 - Application Layer Protocol
| |
| Workforce Protection | web-activity-allowed ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
web-activity-denied ↳ s-symantec-web-activity-1 ↳ s-symantec-web-activity ↳ cef-symantec-web-activity-2
| T1071.001 - Application Layer Protocol: Web Protocols
| |