Vendor: VMware

July 25, 2023 · View on GitHub

Product: NSX FW

RulesModelsMITRE TTPsEvent TypesParsers
3216422
Use-CaseEvent Types/ParsersMITRE TTPContent
Cryptominingnetwork-connection-failed
cef-nsx-fw-logs-1

network-connection-successful
cef-nsx-fw-logs-1
T1496 - Resource Hijacking
  • 1 Rules
Lateral Movementnetwork-connection-failed
cef-nsx-fw-logs-1

network-connection-successful
cef-nsx-fw-logs-1
T1071 - Application Layer Protocol
T1090.002 - Proxy: External Proxy
T1571 - Non-Standard Port
  • 29 Rules
  • 16 Models
Malwarenetwork-connection-failed
cef-nsx-fw-logs-1

network-connection-successful
cef-nsx-fw-logs-1
T1071 - Application Layer Protocol
  • 1 Rules
Ransomwarenetwork-connection-failed
cef-nsx-fw-logs-1

network-connection-successful
cef-nsx-fw-logs-1
T1071 - Application Layer Protocol
  • 2 Rules

ATT&CK Matrix for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Non-Standard Port

Proxy: External Proxy

Application Layer Protocol

Proxy

Resource Hijacking