Vendor: Malwarebytes
July 25, 2023 · View on GitHub
Product: Malwarebytes Endpoint Protection
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 50 | 20 | 13 | 2 | 2 |
ATT&CK Matrix for Enterprise
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
| External Remote Services Valid Accounts | User Execution | External Remote Services Valid Accounts Boot or Logon Autostart Execution | Valid Accounts Exploitation for Privilege Escalation Boot or Logon Autostart Execution | Obfuscated Files or Information: Indicator Removal from Tools Indicator Removal on Host: File Deletion Valid Accounts Indicator Removal on Host Obfuscated Files or Information | OS Credential Dumping Input Capture | Account Discovery Query Registry | Remote Services Remote Services: SMB/Windows Admin Shares | Input Capture Archive Collected Data |