Vendor: Linux
July 25, 2023 · View on GitHub
Product: SSH
Use-Case: Compromised Credentials
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 8 | 3 | 4 | 1 | 1 |
| Event Type | Rules | Models |
|---|---|---|
| remote-logon | T1078 - Valid Accounts ↳ UA-UI-F: First activity from ISP ↳ UA-UC-Suspicious: Activity from suspicious country ↳ UA-UC-Two: Activity from two different countries ↳ UA-UC-Three: Activity from 3 different countries T1133 - External Remote Services ↳ UA-UI-F: First activity from ISP ↳ UA-UC-Suspicious: Activity from suspicious country ↳ UA-UC-Two: Activity from two different countries ↳ UA-UC-Three: Activity from 3 different countries T1078.002 - T1078.002 ↳ SL-UH-I: Interactive logon using a service account ↳ SL-UH-F: First access from asset for a service account ↳ SL-UH-A: Abnormal access from asset for a service account T1558 - Steal or Forge Kerberos Tickets ↳ EXPERT-PENTEST-DOMAINS: Possible credentials theft attack detected | • UA-UI-new: ISP of users during application activity • AL-UsH: Source hosts per User • IL-UH-SA: Interactive logon hosts for service accounts |