Use Case: Phishing

July 25, 2023 ยท View on GitHub

Use Case: Phishing

Vendor: Abnormal Security

ProductEvent TypesMITRE TTPContent
Abnormal Security
  • dlp-email-alert-out
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Accellion

ProductEvent TypesMITRE TTPContent
Accellion
  • account-password-change
  • account-password-reset
  • app-activity
  • app-login
  • dlp-email-alert-out
  • failed-app-login
  • file-delete
  • file-download
  • file-read
  • file-upload
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Kiteworks
  • dlp-alert
  • dlp-email-alert-out
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Akamai

ProductEvent TypesMITRE TTPContent
Cloud Akamai
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Apache

ProductEvent TypesMITRE TTPContent
Apache
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Barracuda

ProductEvent TypesMITRE TTPContent
Barracuda Firewall
  • account-password-change
  • account-password-change-failed
  • failed-logon
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Bitdefender

ProductEvent TypesMITRE TTPContent
Bitdefender GravityZone
  • security-alert
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Bitglass

ProductEvent TypesMITRE TTPContent
Bitglass CASB
  • app-login
  • dlp-alert
  • dlp-email-alert-out
  • failed-app-login
  • file-read
  • file-write
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: CatoNetworks

ProductEvent TypesMITRE TTPContent
Cato Cloud
  • network-alert
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 3 Rules
  • 2 Models

Vendor: Check Point Software

ProductEvent TypesMITRE TTPContent
Check Point Identity Awareness
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models
Check Point NGFW
  • app-login
  • dlp-email-alert-in
  • dlp-email-alert-out
  • failed-vpn-login
  • local-logon
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 17 Rules
  • 9 Models
Check Point Security Gateway
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models
Check Point Threat Prevention
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Cisco

ProductEvent TypesMITRE TTPContent
AnyConnect
  • process-network
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models
Cisco ADC
  • web-activity-allowed
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Cisco Adaptive Security Appliance
  • authentication-failed
  • authentication-successful
  • dns-response
  • failed-logon
  • failed-vpn-login
  • file-download
  • file-upload
  • nac-logon
  • network-connection-successful
  • process-created
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 3 Rules
  • 2 Models
Cisco Cloud Web Security
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Cisco Firepower
  • authentication-successful
  • dns-query
  • dns-response
  • nac-logon
  • netflow-connection
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • security-alert
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 3 Rules
  • 2 Models
Cisco ISE
  • app-activity
  • authentication-failed
  • authentication-successful
  • computer-logon
  • failed-vpn-login
  • nac-failed-logon
  • nac-logon
  • remote-logon
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models
Cisco Meraki MX appliances
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 3 Rules
  • 2 Models
Cisco Secure Email
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Cisco Secure Web Appliance
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Cisco Umbrella
  • config-change
  • dns-query
  • dns-response
  • failed-logon
  • network-connection-failed
  • network-connection-successful
  • remote-logon
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
IronPort Email
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
IronPort Web Security
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Proxy Umbrella
  • network-connection-successful
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Citrix

ProductEvent TypesMITRE TTPContent
Citrix Netscaler
  • app-activity
  • app-login
  • authentication-failed
  • failed-vpn-login
  • process-created
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models
Citrix Netscaler VPN
  • authentication-failed
  • authentication-successful
  • remote-access
  • remote-logon
  • vpn-connection
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models
Web Logging
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Clearswift SEG

ProductEvent TypesMITRE TTPContent
Clearswift SEG
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Cloudflare

ProductEvent TypesMITRE TTPContent
Cloudflare WAF
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Code42

ProductEvent TypesMITRE TTPContent
Code42 Incydr
  • dlp-email-alert-out
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • print-activity
  • usb-activity
  • usb-insert
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Dell

ProductEvent TypesMITRE TTPContent
SonicWALL Aventail
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Digital Arts

ProductEvent TypesMITRE TTPContent
Digital Arts i-FILTER for Business
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Digital Guardian

ProductEvent TypesMITRE TTPContent
Digital Guardian Endpoint Protection
  • app-activity
  • dlp-alert
  • dlp-email-alert-out
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • local-logon
  • print-activity
  • process-created
  • usb-insert
  • usb-write
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Digital Guardian Network DLP
  • dlp-alert
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • print-activity
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Dropbox

ProductEvent TypesMITRE TTPContent
Dropbox
  • app-activity
  • app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-write
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Dtex Systems

ProductEvent TypesMITRE TTPContent
DTEX InTERCEPT
  • file-write
  • local-logon
  • print-activity
  • process-created
  • remote-logon
  • usb-write
  • web-activity-allowed
  • workstation-locked
  • workstation-unlocked
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: ESET

ProductEvent TypesMITRE TTPContent
ESET Endpoint Security
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-logon
  • security-alert
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: EdgeWave

ProductEvent TypesMITRE TTPContent
EdgeWave iPrism
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: F5

ProductEvent TypesMITRE TTPContent
F5 BIG-IP Access Policy Manager (APM)
  • authentication-failed
  • authentication-successful
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models
WebSafe
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Fidelis

ProductEvent TypesMITRE TTPContent
Fidelis XPS
  • dlp-email-alert-in
  • dlp-email-alert-out
  • security-alert
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: FireEye

ProductEvent TypesMITRE TTPContent
FireEye Network Security (NX)
  • security-alert
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Forcepoint

ProductEvent TypesMITRE TTPContent
Forcepoint DLP
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • usb-insert
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Forcepoint Email Security
  • dlp-email-alert-in
  • dlp-email-alert-out
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Websense Secure Gateway
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Fortinet

ProductEvent TypesMITRE TTPContent
Fortinet FortiWeb
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Fortinet UTM
  • app-activity
  • app-activity-failed
  • authentication-failed
  • authentication-successful
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-vpn-login
  • network-alert
  • security-alert
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 17 Rules
  • 9 Models
Fortinet VPN
  • authentication-successful
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Google

ProductEvent TypesMITRE TTPContent
GCP Squid Proxy
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: HP

ProductEvent TypesMITRE TTPContent
IronPort Web Security
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: HashiCorp

ProductEvent TypesMITRE TTPContent
Terraform
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: IBM

ProductEvent TypesMITRE TTPContent
IBM Security Access Manager
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: IMSVA

ProductEvent TypesMITRE TTPContent
IMSVA
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Imperva

ProductEvent TypesMITRE TTPContent
Incapsula
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: InfoWatch

ProductEvent TypesMITRE TTPContent
InfoWatch
  • app-login
  • dlp-email-alert-in
  • dlp-email-alert-out
  • print-activity
  • usb-write
  • web-activity-allowed
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 15 Rules
  • 7 Models

Vendor: IronPort Web Security

ProductEvent TypesMITRE TTPContent
IronPort Web Security
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Juniper Networks

ProductEvent TypesMITRE TTPContent
Juniper SRX
  • account-deleted
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • security-alert
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 3 Rules
  • 2 Models
Juniper VPN
  • account-deleted
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
  • web-activity-allowed
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 3 Rules
  • 2 Models

Vendor: LanScope

ProductEvent TypesMITRE TTPContent
LanScope Cat
  • app-activity
  • dlp-alert
  • failed-usb-activity
  • local-logon
  • print-activity
  • usb-activity
  • usb-write
  • web-activity-allowed
  • workstation-locked
  • workstation-unlocked
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: McAfee

ProductEvent TypesMITRE TTPContent
McAfee DLP
  • dlp-alert
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-usb-activity
  • print-activity
  • usb-write
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
McAfee Email Protection
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
McAfee Web Gateway
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Microsoft

ProductEvent TypesMITRE TTPContent
Exchange
  • app-activity
  • app-activity-failed
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-app-login
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
IIS
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Microsoft Office 365
  • account-disabled
  • account-password-change
  • account-unlocked
  • app-activity
  • app-activity-failed
  • app-login
  • database-query
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dns-query
  • failed-app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • member-added
  • member-removed
  • network-connection-failed
  • network-connection-successful
  • process-created
  • remote-logon
  • security-alert
  • usb-activity
  • usb-insert
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Microsoft Windows
  • account-creation
  • account-deleted
  • account-disabled
  • account-enabled
  • account-lockout
  • account-password-change
  • account-password-change-failed
  • account-password-reset
  • account-switch
  • account-unlocked
  • app-login
  • audit-log-clear
  • audit-policy-change
  • authentication-failed
  • authentication-successful
  • batch-logon
  • computer-logon
  • config-change
  • database-login
  • dcom-activation-failed
  • dns-query
  • dns-response
  • ds-access
  • failed-app-login
  • failed-logon
  • failed-vpn-login
  • file-close
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • local-logon
  • logout-remote
  • member-added
  • member-removed
  • nac-failed-logon
  • nac-logon
  • network-connection-successful
  • ntlm-logon
  • privileged-access
  • privileged-object-access
  • process-created
  • process-network
  • process-network-failed
  • remote-access
  • remote-logon
  • security-alert
  • service-created
  • service-logon
  • share-access
  • share-access-denied
  • task-created
  • usb-activity
  • usb-insert
  • vpn-login
  • vpn-logout
  • winsession-disconnect
  • workstation-locked
  • workstation-unlocked
T1566 - Phishing
  • 2 Rules
  • 2 Models
Web Application Proxy
  • remote-logon
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Web Application Proxy-TLS Gateway
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Mimecast

ProductEvent TypesMITRE TTPContent
Targeted Threat Protection - URL
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: NCP

ProductEvent TypesMITRE TTPContent
NCP
  • authentication-failed
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: NetMotion Wireless

ProductEvent TypesMITRE TTPContent
NetMotion Wireless
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Netskope

ProductEvent TypesMITRE TTPContent
Netskope Security Cloud
  • app-activity
  • app-login
  • dlp-alert
  • dlp-email-alert-out
  • failed-app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • network-connection-failed
  • network-connection-successful
  • security-alert
  • web-activity-allowed
  • web-activity-denied
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 15 Rules
  • 7 Models

Vendor: Nortel Contivity

ProductEvent TypesMITRE TTPContent
Nortel Contivity VPN
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Palo Alto Networks

ProductEvent TypesMITRE TTPContent
GlobalProtect
  • app-activity
  • authentication-failed
  • authentication-successful
  • config-change
  • failed-logon
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • remote-logon
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models
NGFW
  • app-activity
  • config-change
  • dlp-alert
  • failed-vpn-login
  • file-alert
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • remote-logon
  • security-alert
  • vpn-login
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Proofpoint

ProductEvent TypesMITRE TTPContent
Proofpoint TAP
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: RSA

ProductEvent TypesMITRE TTPContent
RSA DLP
  • dlp-alert
  • dlp-email-alert-out
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
SecurID
  • authentication-failed
  • authentication-successful
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: SIGSCI

ProductEvent TypesMITRE TTPContent
SIGSCI
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: SSL Open VPN

ProductEvent TypesMITRE TTPContent
SSL Open VPN
  • app-activity
  • app-activity-failed
  • authentication-failed
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: SafeSend

ProductEvent TypesMITRE TTPContent
SafeSend
  • dlp-email-alert-out
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Sangfor

ProductEvent TypesMITRE TTPContent
NGAF
  • network-alert
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: SecureNet

ProductEvent TypesMITRE TTPContent
SecureNet
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: SentinelOne

ProductEvent TypesMITRE TTPContent
SentinelOne
  • app-activity
  • dns-query
  • dns-response
  • file-alert
  • file-delete
  • file-read
  • file-write
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • process-created
  • security-alert
  • task-created
  • web-activity-allowed
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: SkySea

ProductEvent TypesMITRE TTPContent
ClientView
  • app-activity
  • app-login
  • dlp-email-alert-out
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • print-activity
  • security-alert
  • share-access
  • web-activity-allowed
  • web-activity-denied
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 15 Rules
  • 7 Models

Vendor: Sonicwall

ProductEvent TypesMITRE TTPContent
Sonicwall
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • remote-logon
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Sophos

ProductEvent TypesMITRE TTPContent
Sophos UTM
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Sophos XG Firewall
  • dlp-alert
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • security-alert
  • vpn-login
  • vpn-logout
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566 - Phishing
T1566.002 - Phishing: Spearphishing Link
  • 3 Rules
  • 2 Models

Vendor: Squid

ProductEvent TypesMITRE TTPContent
Squid
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Swipes

ProductEvent TypesMITRE TTPContent
Sonicwall
  • failed-vpn-login
  • remote-logon
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Symantec

ProductEvent TypesMITRE TTPContent
Symantec Blue Coat ProxySG Appliance
  • network-connection-failed
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Symantec Brightmail
  • dlp-email-alert-in
  • dlp-email-alert-out
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Symantec DLP
  • config-change
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-logon
  • failed-usb-activity
  • member-added
  • member-removed
  • network-alert
  • process-alert
  • security-alert
  • usb-activity
  • usb-insert
  • usb-read
  • usb-write
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Symantec Email Security.cloud
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • security-alert
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models
Symantec Fireglass
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Symantec WSS
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Trend Micro

ProductEvent TypesMITRE TTPContent
OfficeScan
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • privileged-object-access
  • security-alert
  • usb-write
  • web-activity-allowed
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 15 Rules
  • 7 Models
Trend Micro Apex One
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • security-alert
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Unix

ProductEvent TypesMITRE TTPContent
Unix
  • account-creation
  • account-deleted
  • account-lockout
  • account-password-change
  • account-switch
  • authentication-failed
  • authentication-successful
  • batch-logon
  • computer-logon
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-logon
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • local-logon
  • member-added
  • member-removed
  • process-created
  • process-created-failed
  • remote-access
  • remote-logon
  • security-alert
  • task-created
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 14 Rules
  • 7 Models

Vendor: Varonis

ProductEvent TypesMITRE TTPContent
Data Security Platform
  • authentication-failed
  • authentication-successful
  • dlp-alert
  • file-delete
  • file-permission-change
  • file-read
  • file-write
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models

Vendor: Watchguard

ProductEvent TypesMITRE TTPContent
Watchguard
  • security-alert
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Weblogin

ProductEvent TypesMITRE TTPContent
Weblogin
  • web-activity-allowed
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Websense Secure Gateway

ProductEvent TypesMITRE TTPContent
Websense Secure Gateway
  • web-activity-allowed
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules

Vendor: Zeek

ProductEvent TypesMITRE TTPContent
Zeek Network Security Monitor
  • app-activity
  • authentication-failed
  • authentication-successful
  • computer-logon
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dns-query
  • dns-response
  • failed-logon
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • nac-failed-logon
  • nac-logon
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • ntlm-logon
  • remote-access
  • remote-logon
  • share-access
  • web-activity-allowed
  • web-activity-denied
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 15 Rules
  • 7 Models

Vendor: Zscaler

ProductEvent TypesMITRE TTPContent
Zscaler Internet Access
  • app-login
  • dlp-alert
  • network-connection-failed
  • network-connection-successful
  • web-activity-allowed
  • web-activity-denied
T1071.001 - Application Layer Protocol: Web Protocols
T1566.002 - Phishing: Spearphishing Link
  • 1 Rules
Zscaler Private Access
  • vpn-login
  • vpn-logout
T1566 - Phishing
  • 2 Rules
  • 2 Models