Use Case: Phishing
July 25, 2023 ยท View on GitHub
Use Case: Phishing
Vendor: Abnormal Security
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Abnormal Security |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Accellion
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Accellion |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Kiteworks |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Akamai
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cloud Akamai |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Apache
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Apache |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Barracuda
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Barracuda Firewall |
| T1566 - Phishing |
|
Vendor: Bitdefender
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Bitdefender GravityZone |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Bitglass
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Bitglass CASB |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: CatoNetworks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cato Cloud |
| T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Check Point Software
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Check Point Identity Awareness |
| T1566 - Phishing |
|
| Check Point NGFW |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
| Check Point Security Gateway |
| T1566 - Phishing |
|
| Check Point Threat Prevention |
| T1566 - Phishing |
|
Vendor: Cisco
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| AnyConnect |
| T1566 - Phishing |
|
| Cisco ADC |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Cisco Adaptive Security Appliance |
| T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
| Cisco Cloud Web Security |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Cisco Firepower |
| T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
| Cisco ISE |
| T1566 - Phishing |
|
| Cisco Meraki MX appliances |
| T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
| Cisco Secure Email |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Cisco Secure Web Appliance |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Cisco Umbrella |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| IronPort Email |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| IronPort Web Security |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Proxy Umbrella |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Citrix
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Citrix Netscaler |
| T1566 - Phishing |
|
| Citrix Netscaler VPN |
| T1566 - Phishing |
|
| Web Logging |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Clearswift SEG
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Clearswift SEG |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Cloudflare
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Cloudflare WAF |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Code42
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Code42 Incydr |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Dell
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SonicWALL Aventail |
| T1566 - Phishing |
|
Vendor: Digital Arts
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Digital Arts i-FILTER for Business |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Digital Guardian
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Digital Guardian Endpoint Protection |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Digital Guardian Network DLP |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Dropbox
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Dropbox |
| T1566 - Phishing |
|
Vendor: Dtex Systems
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| DTEX InTERCEPT |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: ESET
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ESET Endpoint Security |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: EdgeWave
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| EdgeWave iPrism |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: F5
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| F5 BIG-IP Access Policy Manager (APM) |
| T1566 - Phishing |
|
| WebSafe |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Fidelis
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Fidelis XPS |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: FireEye
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| FireEye Network Security (NX) |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Forcepoint
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Forcepoint DLP |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Forcepoint Email Security |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Websense Secure Gateway |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Fortinet
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Fortinet FortiWeb |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Fortinet UTM |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
| Fortinet VPN |
| T1566 - Phishing |
|
Vendor: Google
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| GCP Squid Proxy |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: HP
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IronPort Web Security |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: HashiCorp
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Terraform |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: IBM
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IBM Security Access Manager |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: IMSVA
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IMSVA |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Imperva
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Incapsula |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: InfoWatch
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| InfoWatch |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: IronPort Web Security
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| IronPort Web Security |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Juniper Networks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Juniper SRX |
| T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
| Juniper VPN |
| T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
Vendor: LanScope
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| LanScope Cat |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: McAfee
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| McAfee DLP |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| McAfee Email Protection |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| McAfee Web Gateway |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Microsoft
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Exchange |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| IIS |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Microsoft Office 365 |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Microsoft Windows |
| T1566 - Phishing |
|
| Web Application Proxy |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Web Application Proxy-TLS Gateway |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Mimecast
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Targeted Threat Protection - URL |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: NCP
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NCP |
| T1566 - Phishing |
|
Vendor: NetMotion Wireless
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NetMotion Wireless |
| T1566 - Phishing |
|
Vendor: Netskope
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Netskope Security Cloud |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Nortel Contivity
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Nortel Contivity VPN |
| T1566 - Phishing |
|
Vendor: Palo Alto Networks
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| GlobalProtect |
| T1566 - Phishing |
|
| NGFW |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Proofpoint
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Proofpoint TAP |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: RSA
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| RSA DLP |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| SecurID |
| T1566 - Phishing |
|
Vendor: SIGSCI
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SIGSCI |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: SSL Open VPN
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SSL Open VPN |
| T1566 - Phishing |
|
Vendor: SafeSend
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SafeSend |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Sangfor
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| NGAF |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: SecureNet
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SecureNet |
| T1566 - Phishing |
|
Vendor: SentinelOne
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| SentinelOne |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: SkySea
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| ClientView |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Sonicwall
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Sonicwall |
| T1566 - Phishing |
|
Vendor: Sophos
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Sophos UTM |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Sophos XG Firewall |
| T1071.001 - Application Layer Protocol: Web Protocols T1566 - Phishing T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Squid
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Squid |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Swipes
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Sonicwall |
| T1566 - Phishing |
|
Vendor: Symantec
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Symantec Blue Coat ProxySG Appliance |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Symantec Brightmail |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Symantec DLP |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Symantec Email Security.cloud |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Symantec Fireglass |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Symantec WSS |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Trend Micro
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| OfficeScan |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Trend Micro Apex One |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Unix
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Unix |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Varonis
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Data Security Platform |
| T1566 - Phishing |
|
Vendor: Watchguard
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Watchguard |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Weblogin
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Weblogin |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Websense Secure Gateway
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Websense Secure Gateway |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Zeek
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Zeek Network Security Monitor |
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
Vendor: Zscaler
| Product | Event Types | MITRE TTP | Content |
|---|---|---|---|
| Zscaler Internet Access |
| T1071.001 - Application Layer Protocol: Web Protocols T1566.002 - Phishing: Spearphishing Link |
|
| Zscaler Private Access |
| T1566 - Phishing |
|