Vendor: Microsoft

July 25, 2023 · View on GitHub

Product: DirectAccess

Use-Case: Compromised Credentials

RulesModelsMITRE TTPsEvent TypesParsers
3111322
Event TypeRulesModels
security-alertT1078 - Valid Accounts
A-SA-AN-ALERT-F: First security alert name on the asset
A-SA-ON-ALERT-F: First security alert (by name) in the organization
A-SA-ON-ALERT-A: Abnormal security alert (by name) in the organization
A-SA-ZN-ALERT-F: First security alert (by name) in the zone
A-SA-ZN-ALERT-A: Abnormal security alert (by name) in the zone
A-SA-HN-ALERT-F: First security alert (by name) in the asset
A-SA-HN-ALERT-A: Abnormal security alert (by name) in the asset
A-SA-OA-ALERT-F: First security alert for this asset for organization
SA-OU-ALERT-F: First security alert triggered for this user in the organization
SA-OU-ALERT-A: Abnormal user triggering security alert in the organization
SA-OG-ALERT-F: First security alert triggered for peer group in the organization
SA-OG-ALERT-A: Abnormal peer group triggering security alert in the organization
SA-UA-F: First security alert name for user
SA-UA-A: Abnormal security alert name for user
SA-GA-F: First security alert name in the peer group
SA-GA-A: Abnormal security alert name in the peer group
SA-OA-F: First security alert name in the organization
SA-OA-A: Abnormal security alert name in the organization

T1133 - External Remote Services
ALERT-VPN: Security Alert on asset accessed by this user during VPN session

T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
A-ALERT-Critical: Security Alert on a critical asset
SA-OA: Security alert names in the organization
SA-GA: Security alert names in the peer group
SA-OG-ALERT: Peer groups triggering security alerts in the organization
SA-OU-ALERT: Users triggering security alerts in the organization
A-SA-OA-ALERT: Assets triggering security alerts in the organization
A-SA-HN-ALERT: Security alert names triggered by the asset
A-SA-ZN-ALERT: Security alert names triggered in the zone
A-SA-ON-ALERT: Security alert names triggered in the organization
A-SA-AN-ALERT: Security alert names on asset
vpn-loginT1078 - Valid Accounts
UA-UI-F: First activity from ISP
UA-UC-Suspicious: Activity from suspicious country
UA-UC-Two: Activity from two different countries
UA-UC-Three: Activity from 3 different countries

T1133 - External Remote Services
SL-UA-F-VPN: First VPN connection for service account
VPN02: VPN source IP address is malicious
VPN09: VPN access by executive user
UA-UI-F: First activity from ISP
VPN-GsH-F: First VPN connection from device for peer group
VPN29: VPN connection from a known anonymous proxy
VPN30: VPN connections from multiple WAN IPs
VPN31: VPN connection using a disabled account
UA-UC-Suspicious: Activity from suspicious country
UA-UC-Two: Activity from two different countries
UA-UC-Three: Activity from 3 different countries
VPN-GsH: VPN endpoints in this peer group
UA-UI-new: ISP of users during application activity