Vendor: SecureNet
July 25, 2023 · View on GitHub
Product: SecureNet
Use-Case: Compromised Credentials
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 12 | 2 | 2 | 2 | 2 |
| Event Type | Rules | Models |
|---|---|---|
| failed-app-login | T1078 - Valid Accounts ↳ APP-F-FL: Failed login to application | |
| vpn-login | T1078 - Valid Accounts ↳ UA-UI-F: First activity from ISP ↳ UA-UC-Suspicious: Activity from suspicious country ↳ UA-UC-Two: Activity from two different countries ↳ UA-UC-Three: Activity from 3 different countries T1133 - External Remote Services ↳ SL-UA-F-VPN: First VPN connection for service account ↳ VPN02: VPN source IP address is malicious ↳ VPN09: VPN access by executive user ↳ UA-UI-F: First activity from ISP ↳ VPN-GsH-F: First VPN connection from device for peer group ↳ VPN29: VPN connection from a known anonymous proxy ↳ VPN30: VPN connections from multiple WAN IPs ↳ VPN31: VPN connection using a disabled account ↳ UA-UC-Suspicious: Activity from suspicious country ↳ UA-UC-Two: Activity from two different countries ↳ UA-UC-Three: Activity from 3 different countries | • VPN-GsH: VPN endpoints in this peer group • UA-UI-new: ISP of users during application activity |