Vendor: Microsoft
July 25, 2023 · View on GitHub
Product: DirectAccess
Use-Case: Compromised Credentials
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 31 | 11 | 3 | 2 | 2 |
| Event Type | Rules | Models |
|---|---|---|
| security-alert | T1078 - Valid Accounts ↳ A-SA-AN-ALERT-F: First security alert name on the asset ↳ A-SA-ON-ALERT-F: First security alert (by name) in the organization ↳ A-SA-ON-ALERT-A: Abnormal security alert (by name) in the organization ↳ A-SA-ZN-ALERT-F: First security alert (by name) in the zone ↳ A-SA-ZN-ALERT-A: Abnormal security alert (by name) in the zone ↳ A-SA-HN-ALERT-F: First security alert (by name) in the asset ↳ A-SA-HN-ALERT-A: Abnormal security alert (by name) in the asset ↳ A-SA-OA-ALERT-F: First security alert for this asset for organization ↳ SA-OU-ALERT-F: First security alert triggered for this user in the organization ↳ SA-OU-ALERT-A: Abnormal user triggering security alert in the organization ↳ SA-OG-ALERT-F: First security alert triggered for peer group in the organization ↳ SA-OG-ALERT-A: Abnormal peer group triggering security alert in the organization ↳ SA-UA-F: First security alert name for user ↳ SA-UA-A: Abnormal security alert name for user ↳ SA-GA-F: First security alert name in the peer group ↳ SA-GA-A: Abnormal security alert name in the peer group ↳ SA-OA-F: First security alert name in the organization ↳ SA-OA-A: Abnormal security alert name in the organization T1133 - External Remote Services ↳ ALERT-VPN: Security Alert on asset accessed by this user during VPN session T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools ↳ A-ALERT-Critical: Security Alert on a critical asset | • SA-OA: Security alert names in the organization • SA-GA: Security alert names in the peer group • SA-OG-ALERT: Peer groups triggering security alerts in the organization • SA-OU-ALERT: Users triggering security alerts in the organization • A-SA-OA-ALERT: Assets triggering security alerts in the organization • A-SA-HN-ALERT: Security alert names triggered by the asset • A-SA-ZN-ALERT: Security alert names triggered in the zone • A-SA-ON-ALERT: Security alert names triggered in the organization • A-SA-AN-ALERT: Security alert names on asset |
| vpn-login | T1078 - Valid Accounts ↳ UA-UI-F: First activity from ISP ↳ UA-UC-Suspicious: Activity from suspicious country ↳ UA-UC-Two: Activity from two different countries ↳ UA-UC-Three: Activity from 3 different countries T1133 - External Remote Services ↳ SL-UA-F-VPN: First VPN connection for service account ↳ VPN02: VPN source IP address is malicious ↳ VPN09: VPN access by executive user ↳ UA-UI-F: First activity from ISP ↳ VPN-GsH-F: First VPN connection from device for peer group ↳ VPN29: VPN connection from a known anonymous proxy ↳ VPN30: VPN connections from multiple WAN IPs ↳ VPN31: VPN connection using a disabled account ↳ UA-UC-Suspicious: Activity from suspicious country ↳ UA-UC-Two: Activity from two different countries ↳ UA-UC-Three: Activity from 3 different countries | • VPN-GsH: VPN endpoints in this peer group • UA-UI-new: ISP of users during application activity |