Vendor: Linux
July 25, 2023 · View on GitHub
Product: SSH
Use-Case: Privileged Activity
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 9 | 4 | 3 | 1 | 1 |
| Event Type | Rules | Models |
|---|---|---|
| remote-logon | T1078 - Valid Accounts ↳ AL-F-F-DC-G: First logon to a Domain Controller for peer group ↳ AL-F-A-DC-G: Abnormal logon to a Domain Controller for Peer Group ↳ AL-UH-F-DC: First logon to this Domain Controller for user ↳ AL-UH-A-DC: Abnormal logon to a Domain Controller that user has not accessed often previously ↳ AL-UH-DC-NC: Logon to a Domain Controller for user with no information ↳ RL-OZ-F-DC: First logon to a Domain Controller from zone for organization ↳ RL-OZ-A-DC: Abnormal logon to a Domain Controller from zone for organization ↳ AL-HT-EXEC-new: New user logon to executive asset T1021 - Remote Services ↳ RL-OZ-F-DC: First logon to a Domain Controller from zone for organization ↳ RL-OZ-A-DC: Abnormal logon to a Domain Controller from zone for organization T1068 - Exploitation for Privilege Escalation ↳ ALERT-EXEC: Security violation by Executive | • AL-HT-EXEC: Executive Assets • RL-OZ-DC: Source zones in the organization during domain controller access • RA-UH: Assets accessed by this user remotely • AL-UH-DC: Logons to Domain Controllers |