Vendor: Microsoft
July 25, 2023 · View on GitHub
Product: Windows Defender
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 491 | 67 | 104 | 4 | 4 |
| Use-Case | Event Types/Parsers | MITRE TTP | Content |
|---|---|---|---|
| Account Manipulation | computer-logon ↳microsoft-scep-epp-alert ↳forefront-epp-cef-alert ↳raw-scep-epp-alert-csv ↳raw-scep-alert ↳json-microsoft-scep-epp-alert ↳raw-scep-epp-alert ↳s-scep-epp-alert file-alert ↳win-def-mal-detect process-created ↳s-o365-dlp-alert ↳s-o365-dlp-alert-1 security-alert ↳microsoft-scep-security-alert ↳cef-windows-defender | T1003 - OS Credential Dumping T1047 - Windows Management Instrumentation T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1175 - T1175 T1531 - Account Access Removal |
|
| Audit Tampering | computer-logon ↳microsoft-scep-epp-alert ↳forefront-epp-cef-alert ↳raw-scep-epp-alert-csv ↳raw-scep-alert ↳json-microsoft-scep-epp-alert ↳raw-scep-epp-alert ↳s-scep-epp-alert file-alert ↳win-def-mal-detect process-created ↳s-o365-dlp-alert ↳s-o365-dlp-alert-1 security-alert ↳microsoft-scep-security-alert ↳cef-windows-defender | T1047 - Windows Management Instrumentation T1070 - Indicator Removal on Host T1070.001 - Indicator Removal on Host: Clear Windows Event Logs |
|
| Next Page -->> |