Use Case: Malware
July 25, 2023 ยท View on GitHub
Use Case: Malware
Vendor: APC
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| APC |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Absolute
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Absolute SIEM Connector |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Accellion
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Accellion |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Kiteworks |
| T1204 - User Execution |
|
Vendor: Adaxes
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Adaxes |
| T1078 - Valid Accounts |
|
Vendor: Airlock
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Airlock |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Airlock Web Application Firewall |
| T1071 - Application Layer Protocol |
|
Vendor: Akamai
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Akamai Siem |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Cloud Akamai |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Alert Logic
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Alert Logic |
| T1204 - User Execution |
|
Vendor: AlgoSec
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Firewall Analyzer |
| T1204 - User Execution |
|
Vendor: Amazon
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| AWS Bastion |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| AWS CloudTrail |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| AWS CloudWatch |
| T1078 - Valid Accounts T1204 - User Execution |
|
| AWS GuardDuty |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Anywhere365
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Anywhere365 |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Apache Subversion
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Apache Subversion |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Apache
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Apache |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: AppSense Application Manager
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| AppSense Application Manager |
| T1204 - User Execution |
|
Vendor: Arbor
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Arbor |
| T1071 - Application Layer Protocol |
|
Vendor: AssetView
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| AssetView |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: Atlassian
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Atlassian BitBucket |
| T1078 - Valid Accounts |
|
Vendor: Attivo
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| BOTsink |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Avaya VPN
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Avaya VPN |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Avaya
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Avaya Ethernet Routing Switch |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Axway
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Axway SFTP |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: BIND
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| BIND |
| T1071.004 - Application Layer Protocol: DNS T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Barracuda
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Barracuda Firewall |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1210 - Exploitation of Remote Services |
|
Vendor: BeyondTrust
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| BeyondTrust |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| BeyondTrust PasswordSafe |
| T1204 - User Execution |
|
| BeyondTrust PowerBroker |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| BeyondTrust Privilege Management |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| BeyondTrust Privileged Identity |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Bitdefender
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Bitdefender |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Bitdefender GravityZone |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Bitglass
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Bitglass CASB |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: BlackBerry
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| BlackBerry Protect |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: BlueCat Networks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| BlueCat Networks Adonis |
| T1071.004 - Application Layer Protocol: DNS T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Box
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Box Cloud Content Management |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: Bromium
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Bromium Advanced Endpoint Security |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Bromium Secure Platform |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: CatoNetworks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cato Cloud |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Centrify
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Centrify Audit and Monitoring Service |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
| Centrify Authentication Service |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| Centrify Infrastructure Services |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Centrify Zero Trust Privilege Services |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Check Point Software
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Check Point Endpoint Security |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Check Point Identity Awareness |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Check Point NGFW |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Check Point Security Gateway |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Check Point Security Gateway Virtual Edition (vSEC) |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Check Point Threat Prevention |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Cisco
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ACI |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| AnyConnect |
| T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1078 - Valid Accounts T1204 - User Execution |
|
| Cisco ACS |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Cisco ADC |
| T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Cisco Adaptive Security Appliance |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1550.002 - Use Alternate Authentication Material: Pass the Hash T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Cisco Advance Malware Protection (AMP) |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Cisco Airespace |
| T1204 - User Execution |
|
| Cisco Call Manager |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Cisco Cloud Web Security |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Cisco CloudLock |
| T1204 - User Execution |
|
| Cisco Firepower |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Cisco ISE |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Cisco Meraki MX appliances |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Cisco NPE |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Cisco Secure Network Analytics |
| T1204 - User Execution |
|
| Cisco Secure Web Appliance |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Cisco TACACS |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Cisco Umbrella |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Duo Access Security |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| IronPort Web Security |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Proxy Umbrella |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Citrix
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Citrix AppFW |
| T1071 - Application Layer Protocol |
|
| Citrix Endpoint Management |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Citrix Gateway ActiveSync Connector |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Citrix Netscaler |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Citrix Netscaler VPN |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Citrix ShareFile |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Citrix XenApp |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Citrix XenDesktop |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Netscaler WAF |
| T1071 - Application Layer Protocol |
|
| Web Logging |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Cloud Application
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cloud Application |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Cloudflare
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cloudflare CDN |
| T1204 - User Execution |
|
| Cloudflare Insights |
| T1078 - Valid Accounts |
|
| Cloudflare WAF |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Code42
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Code42 Incydr |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: Cofense
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Phishme |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Cognitas CrossLink
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cognitas CrossLink |
| T1078 - Valid Accounts |
|
Vendor: Contrast Security
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Contrast Security |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: CrowdStrike
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Falcon |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: CyberArk
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| CyberArk Endpoint Privilege Management |
| T1204 - User Execution |
|
| CyberArk Vault |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| Privileged Session Manager |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Privileged Threat Analytics |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Cybereason
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cybereason |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: DTEX InTERCEPT
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| DTEX InTERCEPT |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: Damballa
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Failsafe |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Darktrace
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Darktrace |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Darktrace Enterprise Immune System |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Dell
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Dell EMC Isilon |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
| One Identity Manager |
| T1078 - Valid Accounts T1204 - User Execution |
|
| RSA Authentication Manager |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| SonicWALL Aventail |
| T1078 - Valid Accounts |
|
Vendor: Digital Arts
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Digital Arts i-FILTER for Business |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Digital Guardian
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Digital Guardian Endpoint Protection |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Digital Guardian Network DLP |
| T1204 - User Execution |
|
Vendor: Dropbox
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Dropbox |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: Dtex Systems
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| DTEX InTERCEPT |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1550.002 - Use Alternate Authentication Material: Pass the Hash T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: Duo Access Security
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Duo Access Security |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: EMP
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| EMP |
| T1078 - Valid Accounts |
|
Vendor: ESET
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ESET Endpoint Security |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: ESector
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ESector DEFESA |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: EdgeWave
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| EdgeWave iPrism |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Egnyte
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Egnyte |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: EnSilo
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| EnSilo |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: EndPoint
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| EndPoint |
| T1204 - User Execution |
|
Vendor: Endgame
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Endgame EDR |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Entrust
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IdentityGuard |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Epic
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Epic SIEM |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Exabeam
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Exabeam DL |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Extrahop
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Reveal(x) |
| T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1204 - User Execution T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Extreme Networks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Zebra wireless LAN management |
| T1090.003 - Proxy: Multi-hop Proxy T1210 - Exploitation of Remote Services |
|
Vendor: F-Secure
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| F-Secure Client Security |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: F5
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| BIG-IP DNS |
| T1071.004 - Application Layer Protocol: DNS T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| F5 Advanced Web Application Firewall (WAF) |
| T1071 - Application Layer Protocol T1204 - User Execution |
|
| F5 BIG-IP |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| F5 BIG-IP Access Policy Manager (APM) |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| F5 BIG-IP Advanced Firewall Module (AFM) |
| T1071 - Application Layer Protocol |
|
| F5 BIG-IP Application Security Manager (ASM) |
| T1078 - Valid Accounts T1204 - User Execution |
|
| F5 IP Intelligence |
| T1204 - User Execution |
|
| F5 Silverline |
| T1204 - User Execution |
|
| WebSafe |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: FTP
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| FTP |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Fast Enterprises
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Fast Enterprises GenTax |
| T1078 - Valid Accounts |
|
Vendor: Fidelis
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Fidelis Network |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Fidelis XPS |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: FireEye
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| FireEye Email Gateway |
| T1078 - Valid Accounts T1204 - User Execution |
|
| FireEye Email Security (EX) |
| T1078 - Valid Accounts T1204 - User Execution |
|
| FireEye Email Threat Prevention (ETP) |
| T1078 - Valid Accounts T1204 - User Execution |
|
| FireEye Endpoint Security (CM) |
| T1078 - Valid Accounts T1204 - User Execution |
|
| FireEye Endpoint Security (HX) |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
| FireEye Helix |
| T1204 - User Execution |
|
| FireEye Network Security (Helix) |
| T1078 - Valid Accounts T1204 - User Execution |
|
| FireEye Network Security (NX) |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Forcepoint
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Forcepoint CASB |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Forcepoint DLP |
| T1204 - User Execution |
|
| Forcepoint Insider Threat |
| T1204 - User Execution |
|
| Forcepoint NGFW |
| T1071 - Application Layer Protocol |
|
| Websense Secure Gateway |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Forescout
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Forescout CounterACT |
| T1071 - Application Layer Protocol T1204 - User Execution |
|
Vendor: Fortinet
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| FortiAuthenticator |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Fortinet Enterprise Firewall |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Fortinet FortiWeb |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Fortinet UTM |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Fortinet VPN |
| T1078 - Valid Accounts |
|
Vendor: GTB
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| GTBInspector |
| T1204 - User Execution |
|
Vendor: Gamma
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Gamma |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Gemalto
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Gemalto MFA |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: GitHub
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| GitHub |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Google
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| GCP Squid Proxy |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
| |
| Google Calendar |
| T1078 - Valid Accounts |
|
| Google Cloud Platform |
| T1078 - Valid Accounts |
|
| Google Drive |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: HP
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Aruba Wireless controller |
| T1204 - User Execution |
|
| HP |
| T1204 - User Execution |
|
| HP Comware |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| HP Virtual Connect Enterprise Manager |
| T1078 - Valid Accounts |
|
| IronPort Web Security |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: HashiCorp
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| HashiCorp Vault |
| T1078 - Valid Accounts |
|
| Terraform |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: HelpSystems
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Powertech Identity Access Manager (BoKs) |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: Huawei
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Enterprise Network Firewall |
| T1071 - Application Layer Protocol |
|
| Unified Security Gateway |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: IBM
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IBM |
| T1078 - Valid Accounts |
|
| IBM DB2 |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| IBM Endpoint Manager |
| T1078 - Valid Accounts T1204 - User Execution |
|
| IBM Racf |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| IBM Sametime |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| IBM Security Access Manager |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| IBM Sense |
| T1078 - Valid Accounts T1204 - User Execution |
|
| IBM Sterling B2B Integrator |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| Infosphere Guardium |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Lotus Mobile Connect |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Proventia Network IPS |
| T1204 - User Execution |
|
| QRadar Network Security |
| T1204 - User Execution |
|
Vendor: ICDB
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ICDB |
| T1078 - Valid Accounts |
|
Vendor: IPTables
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IPTables |
| T1071 - Application Layer Protocol |
|
Vendor: IXIA
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IXIA ThreatArmor |
| T1071 - Application Layer Protocol |
|
Vendor: Illumio
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Illumio |
| T1071 - Application Layer Protocol |
|
Vendor: Imperva
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| CounterBreach |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Imperva File Activity Monitoring (FAM) |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
| Imperva SecureSphere |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Incapsula |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: InfoWatch
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| InfoWatch |
| T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Infoblox
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Infoblox |
| T1071 - Application Layer Protocol T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1204 - User Execution T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Infoblox BloxOne |
| T1078 - Valid Accounts |
|
Vendor: Inky
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Inky Anti-Phishing |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Ipswitch
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IPswitch MoveIt |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| MoveIt DMZ |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
Vendor: IronPort Web Security
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IronPort Web Security |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Johnson Controls
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Johnson Controls P2000 |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
Vendor: Juniper Networks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Juniper Networks ATP |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Juniper Networks Pulse Secure |
| T1078 - Valid Accounts |
|
| Juniper OWA |
| T1078 - Valid Accounts |
|
| Juniper SRX |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Juniper VPN |
| T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Kaspersky
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Kaspersky Endpoint Security for Business |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Kemp
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Kemp LoadMaster |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Load Balancer |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Kiteworks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Kiteworks |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: LEAP
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IMSS |
| T1078 - Valid Accounts T1204 - User Execution |
|
| LEAP |
| T1078 - Valid Accounts |
|
Vendor: LOGBinder
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SharePoint |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: LanScope Cat
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| LanScope Cat |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: LanScope
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| LanScope Cat |
| T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: LastPass
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| LastPass |
| T1078 - Valid Accounts |
|
Vendor: Lastline
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Lastline |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Linux
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Linux CentOs |
| T1071 - Application Layer Protocol |
|
| SSH |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
Vendor: LogMeIn
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| RemotelyAnywhere |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: LogRhythm
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| LogRhythm |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: Lumension
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Lumension |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Malwarebytes
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Malwarebytes Endpoint Protection |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: McAfee
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| MDAM |
| T1078 - Valid Accounts T1204 - User Execution |
|
| McAfee Advanced Threat Defense |
| T1204 - User Execution |
|
| McAfee DLP |
| T1204 - User Execution |
|
| McAfee Endpoint Security |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1117 - T1117 T1118 - T1118 T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1170 - T1170 T1204 - User Execution T1220 - XSL Script Processing |
|
| McAfee Enterprise Security Manager |
| T1204 - User Execution |
|
| McAfee IDPS |
| T1204 - User Execution |
|
| McAfee NSM |
| T1204 - User Execution |
|
| McAfee Network Security Platform (IPS) |
| T1204 - User Execution |
|
| McAfee Solidifier |
| T1078 - Valid Accounts T1204 - User Execution |
|
| McAfee Web Gateway |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Mcafee EPO |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Skyhigh Networks CASB |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Microsoft
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Advanced Threat Analytics (ATA) |
| T1078 - Valid Accounts T1204 - User Execution |
|
| AppLocker |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Exchange |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| IIS |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Microsoft Azure |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071 - Application Layer Protocol T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Microsoft Azure AD Identity Protection |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Microsoft Azure Active Directory |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Microsoft Azure Advanced Threat Protection |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Microsoft Azure MFA |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Microsoft Azure Security Center |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Microsoft Azure Sentinel |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Microsoft Cloud App Security (MCAS) |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071 - Application Layer Protocol T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Microsoft Defender ATP |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Microsoft Graph |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Microsoft Office 365 |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071 - Application Layer Protocol T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Microsoft OneDrive |
| T1078 - Valid Accounts |
|
| Microsoft RRA |
| T1078 - Valid Accounts |
|
| Microsoft SQL Server |
| T1090.003 - Proxy: Multi-hop Proxy |
|
| Microsoft ScanMail |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Microsoft Sysmon |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071.004 - Application Layer Protocol: DNS T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Microsoft Windows |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071 - Application Layer Protocol T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1207 - Rogue Domain Controller T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1569.002 - T1569.002 T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Microsoft Windows DNSServer |
| T1071.004 - Application Layer Protocol: DNS T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| NetApp |
| T1204 - User Execution |
|
| Web Application Proxy |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Web Application Proxy-TLS Gateway |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Windows Defender |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Mimecast
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Mimecast |
| T1078 - Valid Accounts |
|
| Mimecast Email Security |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Targeted Threat Protection - URL |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: MobileIron
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| MobileIron |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Morphisec
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Morphisec EPTP |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Mvision
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Mvision |
| T1204 - User Execution |
|
Vendor: NCP
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NCP |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: NNT
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NNT ChangeTracker |
| T1078 - Valid Accounts |
|
Vendor: Namespace rDirectory
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Namespace rDirectory |
| T1207 - Rogue Domain Controller |
|
Vendor: NetDocs
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NetDocs |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: NetIQ
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NetIQ |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: NetMotion Wireless
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NetMotion Wireless |
| T1078 - Valid Accounts |
|
Vendor: Netskope
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Netskope Security Cloud |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Netwrix
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Netwrix Auditor |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1207 - Rogue Domain Controller T1210 - Exploitation of Remote Services |
|
| Sonicwall |
| T1204 - User Execution |
|
Vendor: Nexthink
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Nexthink |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: OSSEC
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| OSSEC |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: ObserveIT
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ObserveIT |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: Okta
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Okta Adaptive MFA |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Onapsis
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Onapsis |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: OneLogin
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| OneLogin |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: OneSpan
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| OneSpan |
| T1090.003 - Proxy: Multi-hop Proxy T1210 - Exploitation of Remote Services |
|
Vendor: Oracle
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Oracle Access Manager |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Oracle Solaris |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: Ordr
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Ordr SCE |
| T1204 - User Execution |
|
Vendor: Osirium
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Osirium |
| T1078 - Valid Accounts |
|
Vendor: Palo Alto Networks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cortex XDR |
| T1078 - Valid Accounts T1204 - User Execution |
|
| GlobalProtect |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| Magnifier |
| T1078 - Valid Accounts T1204 - User Execution |
|
| NGFW |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Palo Alto Aperture |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
| Traps |
| T1078 - Valid Accounts T1204 - User Execution |
|
| WildFire |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Password Manager Pro
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Password Manager Pro |
| T1204 - User Execution |
|
Vendor: Paxton
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NET2DOOR |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Perforce
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Perforce |
| T1078 - Valid Accounts |
|
Vendor: Ping Identity
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Ping Identity |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| PingID |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| PingOne |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: PowerSentry
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| PowerSentry |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Prisma Cloud
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Prisma Cloud |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Procad
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Pro.File DMS |
| T1078 - Valid Accounts |
|
Vendor: Proofpoint
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Proofpoint Enterprise Protection |
| T1204 - User Execution |
|
Vendor: ProtectWise
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NDR |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: ProxySG
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ProxySG |
| T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Qualys
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Qualys |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Quest InTrust
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Quest InTrust |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: Quest Software
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Change Auditor |
| T1090.003 - Proxy: Multi-hop Proxy T1207 - Rogue Domain Controller T1210 - Exploitation of Remote Services |
|
Vendor: RSA
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| RSA Authentication Manager |
| T1078 - Valid Accounts T1204 - User Execution |
|
| RSA DLP |
| T1204 - User Execution |
|
| RSA ECAT |
| T1078 - Valid Accounts T1204 - User Execution |
|
| RSA NetWitness |
| T1078 - Valid Accounts |
|
| SecurID |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: RUID
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| RUID |
| T1078 - Valid Accounts |
|
Vendor: Radius
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Radius |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: RangerAudit
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| RangerAudit |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Rapid7
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| InsightVM |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Nexpose |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Red Canary
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Red Canary |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: SAP
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SAP |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: SIGSCI
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SIGSCI |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: SSL Open VPN
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Nasuni |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
| SSL Open VPN |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Safend
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Data Protection Suite (DPS) |
| T1204 - User Execution |
|
Vendor: Sailpoint
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IdentityNow |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| SecurityIQ |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
Vendor: Salesforce
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Salesforce |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Sangfor
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NGAF |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Secure Computing
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Secure Computing SafeWord |
| T1078 - Valid Accounts |
|
Vendor: Secure Envoy
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Secure Envoy |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: SecureAuth
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SecureAuth Login |
| T1078 - Valid Accounts |
|
Vendor: SecureLink
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SecureLink |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: SecureNet
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SecureNet |
| T1078 - Valid Accounts |
|
Vendor: SecureWorks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| iSensor IPS |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: SentinelOne
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SentinelOne |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1550.002 - Use Alternate Authentication Material: Pass the Hash T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
Vendor: ServiceNow
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ServiceNow |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Shibboleth
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Shibboleth IdP |
| T1078 - Valid Accounts |
|
| Shibboleth SSO |
| T1078 - Valid Accounts |
|
Vendor: Silverfort
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Silverfort |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: SiteMinder
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SiteMinder |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: SkySea
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ClientView |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1569.002 - T1569.002 |
|
Vendor: Slack
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| BeyondTrust Secure Remote Access |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Epic SIEM |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
| Exabeam Advanced Analytics |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Slack |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Snort
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Snort |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Sonicwall
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Sonicwall |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Sophos
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Sophos Endpoint Protection |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Sophos Firewall |
| T1071 - Application Layer Protocol |
|
| Sophos Invincea |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Sophos SafeGuard |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Sophos UTM |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Sophos XG Firewall |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Splunk
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Splunk Stream |
| T1071.004 - Application Layer Protocol: DNS T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Squid
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Squid |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: StealthBits
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| StealthIntercept |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution T1207 - Rogue Domain Controller |
|
Vendor: Sun One
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| LDAP |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Suricata
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Suricata |
| T1204 - User Execution |
|
| Suricata IDS |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Swift
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Swift |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Swipes
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Sonicwall |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Swivel
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Swivel |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Symantec
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Symantec Advanced Threat Protection |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Symantec Blue Coat Content Analysis System |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Symantec Blue Coat ProxySG Appliance |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Symantec CloudSOC |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| Symantec Critical System Protection |
| T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| Symantec DLP |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| Symantec EDR |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Symantec Email Security.cloud |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Symantec Endpoint Protection |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1204 - User Execution |
|
| Symantec Fireglass |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Symantec Managed Security Services |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Symantec VIP |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Symantec WSS |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Synology NAS
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Synology NAS |
| T1569 - System Services T1569.002 - T1569.002 |
|
Vendor: Tanium
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Endpoint Platform |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Threat Response |
| T1204 - User Execution |
|
Vendor: Tenable.io
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Tenable.io |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Thycotic Secret Server
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Thycotic Secret Server |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: TrapX
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| TrapX |
| T1204 - User Execution |
|
Vendor: Trend Micro
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cloud App Security |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Deep Discovery Email Inspector |
| T1204 - User Execution |
|
| Deep Discovery Inspector |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Deep Security Agent |
| T1078 - Valid Accounts T1204 - User Execution |
|
| OfficeScan |
| T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Trend Micro |
| T1071 - Application Layer Protocol T1078 - Valid Accounts T1204 - User Execution |
|
| Trend Micro Apex One |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Trend Micro TippingPoint NGIPS |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Tripwire Enterprise
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Tripwire Enterprise |
| T1204 - User Execution |
|
Vendor: Tufin
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SecureTrack |
| T1078 - Valid Accounts |
|
Vendor: Tyco
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| CCURE Building Management System |
| T1078 - Valid Accounts |
|
Vendor: Unix
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Auditbeat |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071 - Application Layer Protocol T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| CDS |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| FTP |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
| Unix |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Unix Auditd |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1090.003 - Proxy: Multi-hop Proxy T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| Unix Privilege Management |
| T1204 - User Execution |
|
Vendor: VMware
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NSX FW |
| T1071 - Application Layer Protocol |
|
| VMWare ID Manager (VIDM) |
| T1204 - User Execution |
|
| VMware Carbon Black App Control |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1071 - Application Layer Protocol T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| VMware Carbon Black Cloud Endpoint Standard |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| VMware Carbon Black EDR |
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1012 - Query Registry T1021 - Remote Services T1027 - Obfuscated Files or Information T1027.004 - Obfuscated Files or Information: Compile After Delivery T1036 - Masquerading T1036.005 - Masquerading: Match Legitimate Name or Location T1046 - Network Service Scanning T1047 - Windows Management Instrumentation T1053 - Scheduled Task/Job T1053.005 - Scheduled Task/Job: Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interperter T1059.001 - Command and Scripting Interperter: PowerShell T1064 - Scripting T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1086 - Command and Scripting Interpreter: PowerShell T1093 - Process Injection: Process Hollowing T1105 - Ingress Tool Transfer T1112 - Modify Registry T1117 - T1117 T1118 - T1118 T1123 - Audio Capture T1127 - Trusted Developer Utilities Proxy Execution T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild T1134.001 - Access Token Manipulation: Token Impersonation/Theft T1140 - Deobfuscate/Decode Files or Information T1170 - T1170 T1171 - T1171 T1175 - T1175 T1197 - BITS Jobs T1202 - Indirect Command Execution T1203 - Exploitation for Client Execution T1204 - User Execution T1210 - Exploitation of Remote Services T1218 - Signed Binary Proxy Execution T1218.002 - Signed Binary Proxy Execution: Control Panel T1218.005 - T1218.005 T1218.007 - Signed Binary Proxy Execution: Msiexec T1218.011 - Signed Binary Proxy Execution: Rundll32 T1220 - XSL Script Processing T1223 - T1223 T1490 - Inhibit System Recovery T1505.003 - Server Software Component: Web Shell T1543.003 - Create or Modify System Process: Windows Service T1546.001 - T1546.001 T1547.001 - T1547.001 T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting T1566.001 - T1566.001 T1569 - System Services T1574 - Hijack Execution Flow T1574.002 - Hijack Execution Flow: DLL Side-Loading T1574.010 - T1574.010 T1574.011 - T1574.011 |
|
| VMware ESXi |
| T1078 - Valid Accounts T1204 - User Execution |
|
| VMware Horizon |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
| VMware NSX |
| T1071 - Application Layer Protocol |
|
| VMware VCenter |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services |
|
| VMware View |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Varonis
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Data Security Platform |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution |
|
Vendor: Vectra
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Vectra Cognito Detect |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: Virtru
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Virtru |
| T1204 - User Execution |
|
Vendor: Vormetric
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Vormetric |
| T1204 - User Execution |
|
Vendor: Watchguard
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Malwarebytes Incident Response |
| T1078 - Valid Accounts T1204 - User Execution |
|
| Watchguard |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Weblogin
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NetApp |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution |
|
| Weblogin |
| T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Websense Secure Gateway
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Websense Secure Gateway |
| T1071.001 - Application Layer Protocol: Web Protocols T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
Vendor: Workday
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Workday |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Xceedium
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Xceedium |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: Zeek
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Zeek Network Security Monitor |
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1071.004 - Application Layer Protocol: DNS T1078 - Valid Accounts T1085 - Signed Binary Proxy Execution: Rundll32 T1090.003 - Proxy: Multi-hop Proxy T1204 - User Execution T1210 - Exploitation of Remote Services T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms T1569 - System Services T1569.002 - T1569.002 |
|
Vendor: Zlock
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Zlock |
| T1078 - Valid Accounts |
|
Vendor: Zscaler
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Zscaler Internet Access |
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1204 - User Execution T1550.002 - Use Alternate Authentication Material: Pass the Hash T1568.002 - Dynamic Resolution: Domain Generation Algorithms |
|
| Zscaler Private Access |
| T1078 - Valid Accounts |
|
Vendor: eDocs
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| eDocs |
| T1078 - Valid Accounts |
|
Vendor: iManage
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| iManage |
| T1078 - Valid Accounts T1204 - User Execution |
|
Vendor: oVirt
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| oVirt |
| T1078 - Valid Accounts T1090.003 - Proxy: Multi-hop Proxy |
|
Vendor: pfSense
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| pfSense |
| T1071 - Application Layer Protocol |
|
Vendor: xsuite
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| xsuite |
| T1078 - Valid Accounts T1204 - User Execution |
|