Vendor: Workday
July 25, 2023 · View on GitHub
Product: Workday
| Rules | Models | MITRE TTPs | Event Types | Parsers |
|---|---|---|---|---|
| 84 | 33 | 16 | 4 | 4 |
| Use-Case | Event Types/Parsers | MITRE TTP | Content |
|---|---|---|---|
| Abnormal Authentication & Access | account-password-change ↳workday-app-login-1 ↳sk4-workday-app-login ↳workday-app-login-2 app-login ↳sk4-workday-failed-app-login failed-app-login ↳workday-app-activity-1 ↳workday-app-activity-2 file-write ↳sk4-workday-app-auth-failed | T1078 - Valid Accounts T1133 - External Remote Services |
|
| Account Manipulation | account-password-change ↳workday-app-login-1 ↳sk4-workday-app-login ↳workday-app-login-2 app-login ↳sk4-workday-failed-app-login failed-app-login ↳workday-app-activity-1 ↳workday-app-activity-2 file-write ↳sk4-workday-app-auth-failed | T1098 - Account Manipulation |
|
| Next Page -->> |
ATT&CK Matrix for Enterprise
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|
| External Remote Services Valid Accounts | User Execution | External Remote Services Valid Accounts Account Manipulation | Valid Accounts Process Injection | Valid Accounts Obfuscated Files or Information Process Injection Signed Binary Proxy Execution Signed Binary Proxy Execution: Rundll32 | OS Credential Dumping | File and Directory Discovery | Email Collection | Proxy: Multi-hop Proxy Application Layer Protocol Proxy | Automated Exfiltration | Data Encrypted for Impact |