Use Case: Malware

July 25, 2023 ยท View on GitHub

Use Case: Malware

Vendor: AMAG

ProductEvent TypesMITRE TTPContent
Symmetry Access Control
  • dlp-alert
  • failed-physical-access
  • physical-access
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: APC

ProductEvent TypesMITRE TTPContent
APC
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: ASUPIM

ProductEvent TypesMITRE TTPContent
ASUPIM
  • failed-logon
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules

Vendor: AVI Networks

ProductEvent TypesMITRE TTPContent
Load Balancer
  • account-switch
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Absolute

ProductEvent TypesMITRE TTPContent
Absolute SIEM Connector
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 27 Rules
  • 7 Models

Vendor: Accellion

ProductEvent TypesMITRE TTPContent
Kiteworks
  • account-password-change
  • account-password-reset
  • account-unlocked
  • app-activity
  • app-login
  • dlp-email-alert-out
  • failed-app-login
  • file-alert
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • security-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 10 Rules
  • 6 Models

Vendor: AirWatch

ProductEvent TypesMITRE TTPContent
AirWatch
  • authentication-failed
  • authentication-successful
  • failed-logon
T1078 - Valid Accounts
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 3 Rules

Vendor: Airlock

ProductEvent TypesMITRE TTPContent
Web Application Firewall
  • app-activity-failed
  • app-login
  • database-query
  • failed-app-login
  • file-delete
  • file-download
  • file-upload
  • file-write
  • network-connection-successful
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 8 Rules
  • 3 Models

Vendor: Akamai

ProductEvent TypesMITRE TTPContent
Akamai Siem
  • authentication-successful
T1078 - Valid Accounts
  • 1 Rules
Cloud Akamai
  • file-delete
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models

Vendor: Alert Logic

ProductEvent TypesMITRE TTPContent
Alert Logic
  • app-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: Amazon

ProductEvent TypesMITRE TTPContent
AWS Bastion
  • app-activity
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
AWS CloudTrail
  • account-password-change
  • app-activity
  • app-login
  • cloud-admin-activity
  • cloud-admin-activity-failed
  • netflow-connection
  • storage-access
  • storage-activity
  • storage-activity-failed
T1071 - Application Layer Protocol
T1078 - Valid Accounts
  • 2 Rules
AWS CloudWatch
  • app-activity-failed
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
AWS GuardDuty
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 239 Rules
  • 33 Models

Vendor: Apache

ProductEvent TypesMITRE TTPContent
Apache
  • network-connection-failed
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Apache Guacamole
  • app-login
  • file-permission-change
T1078 - Valid Accounts
  • 1 Rules
Cassandra
  • database-login
  • database-update
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: AppSense Application Manager

ProductEvent TypesMITRE TTPContent
AppSense Application Manager
  • local-logon
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Apple

ProductEvent TypesMITRE TTPContent
macOS
  • file-alert
T1204 - User Execution
  • 1 Rules
  • 1 Models

Vendor: Arbor

ProductEvent TypesMITRE TTPContent
Arbor
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Armis

ProductEvent TypesMITRE TTPContent
Armis
  • failed-logon
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules

Vendor: AssetView

ProductEvent TypesMITRE TTPContent
AssetView
  • file-download
  • file-write
  • network-connection-failed
  • print-activity
  • security-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 11 Rules
  • 6 Models

Vendor: Atlassian

ProductEvent TypesMITRE TTPContent
Atlassian BitBucket
  • dlp-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Attivo

ProductEvent TypesMITRE TTPContent
BOTsink
  • database-login
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: Auth0

ProductEvent TypesMITRE TTPContent
Auth0
  • account-password-change-failed
  • app-login
  • failed-logon
  • network-connection-successful
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 4 Rules

Vendor: Avaya

ProductEvent TypesMITRE TTPContent
Avaya Ethernet Routing Switch
  • authentication-successful
  • nac-logon
T1078 - Valid Accounts
  • 1 Rules
Avaya VPN
  • dns-query
  • vpn-login
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
  • 2 Rules

Vendor: Axway

ProductEvent TypesMITRE TTPContent
Axway SFTP
  • file-upload
  • process-network-failed
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: BIND

ProductEvent TypesMITRE TTPContent
BIND
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Barracuda

ProductEvent TypesMITRE TTPContent
Barracuda Firewall
  • account-lockout
  • database-query
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
T1071 - Application Layer Protocol
T1078 - Valid Accounts
  • 3 Rules

Vendor: BeyondTrust

ProductEvent TypesMITRE TTPContent
BeyondTrust PasswordSafe
  • privileged-access
T1204 - User Execution
  • 2 Rules
  • 2 Models
BeyondTrust PowerBroker
  • account-enabled
  • dlp-email-alert-out-failed
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
BeyondTrust Privilege Management
  • dns-response
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071.004 - Application Layer Protocol: DNS
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 241 Rules
  • 33 Models
BeyondTrust Privileged Identity
  • account-switch
  • app-activity
  • app-login
  • authentication-successful
  • database-alert
  • failed-app-login
  • failed-physical-access
T1078 - Valid Accounts
T1204 - User Execution
  • 7 Rules
  • 4 Models
BeyondTrust Secure Remote Access
  • app-login
  • failed-app-login
  • failed-physical-access
T1078 - Valid Accounts
  • 1 Rules

Vendor: Bitdefender

ProductEvent TypesMITRE TTPContent
GravityZone
  • authentication-successful
  • process-created
  • security-alert
  • web-activity-denied
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 270 Rules
  • 43 Models

Vendor: Bitglass

ProductEvent TypesMITRE TTPContent
Bitglass CASB
  • app-login
  • authentication-successful
  • dlp-email-alert-out
  • failed-app-login
  • file-download
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models

Vendor: BlackBerry

ProductEvent TypesMITRE TTPContent
BlackBerry Protect
  • app-activity
  • file-delete
  • security-alert
  • vpn-logout
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: BlueCat Networks

ProductEvent TypesMITRE TTPContent
BlueCat Networks Adonis
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
BlueCat Networks DHCP
  • failed-logon
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules

Vendor: Box

ProductEvent TypesMITRE TTPContent
Box Cloud Content Management
  • app-activity
  • app-activity-failed
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • print-activity
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models

Vendor: Bromium

ProductEvent TypesMITRE TTPContent
Bromium Secure Platform
  • file-alert
  • file-permission-change
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models

Vendor: CA Technologies

ProductEvent TypesMITRE TTPContent
CA Privileged Access Manager Server Control
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: CDS

ProductEvent TypesMITRE TTPContent
CDS
  • failed-ds-access
  • failed-logon
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules

Vendor: CatoNetworks

ProductEvent TypesMITRE TTPContent
Cato Cloud
  • failed-logon
  • network-alert
  • vpn-login
  • web-activity-allowed
  • web-activity-denied
  • workstation-unlocked
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 35 Rules
  • 10 Models

Vendor: Centrify

ProductEvent TypesMITRE TTPContent
Centrify Audit and Monitoring Service
  • authentication-successful
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models
Centrify Authentication Service
  • account-switch
  • authentication-failed
  • local-logon
  • process-created
  • remote-logon
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 240 Rules
  • 33 Models
Centrify Infrastructure Services
  • authentication-failed
  • failed-logon
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules
Centrify Zero Trust Privilege Services
  • app-activity
  • app-login
  • failed-app-login
  • file-delete
T1078 - Valid Accounts
  • 1 Rules

Vendor: Check Point Software

ProductEvent TypesMITRE TTPContent
Check Point Endpoint Security
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Check Point Identity Awareness
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 31 Rules
  • 8 Models
Check Point NGFW
  • authentication-successful
  • database-update
  • dlp-email-alert-in
  • failed-vpn-login
  • file-permission-change
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • security-alert
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 37 Rules
  • 12 Models
Check Point Security Gateway
  • failed-vpn-login
  • network-connection-failed
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 33 Rules
  • 8 Models
Check Point Security Gateway Virtual Edition (vSEC)
  • authentication-failed
  • authentication-successful
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 29 Rules
  • 8 Models
Check Point Threat Prevention
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • security-alert
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
  • 6 Rules
  • 4 Models
Next Generation Firewall
  • network-connection-failed
  • network-connection-successful
T1071 - Application Layer Protocol
  • 2 Rules

Vendor: Cimtrak

ProductEvent TypesMITRE TTPContent
Cimtrak
  • file-write
  • security-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 9 Rules
  • 6 Models

Vendor: Cisco

ProductEvent TypesMITRE TTPContent
ACI
  • app-activity
  • authentication-failed
  • authentication-successful
T1078 - Valid Accounts
  • 1 Rules
AnyConnect
  • failed-vpn-login
  • nac-logon
  • process-created
  • vpn-login
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 240 Rules
  • 33 Models
Cisco
  • authentication-successful
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Cisco ACS
  • account-lockout
  • app-activity
  • authentication-failed
T1078 - Valid Accounts
  • 1 Rules
Cisco ADC
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Cisco Adaptive Security Appliance
  • authentication-successful
  • dlp-email-alert-out
  • file-download
  • print-activity
  • process-created
  • remote-logon
  • security-alert
  • vpn-login
  • vpn-logout
  • web-activity-allowed
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 271 Rules
  • 44 Models
Cisco Advance Malware Protection (AMP)
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Cisco Airespace
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Cisco Call Manager
  • app-activity
  • authentication-failed
  • authentication-successful
T1078 - Valid Accounts
  • 1 Rules
Cisco Cloud Web Security
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Cisco CloudLock
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Cisco Console
  • app-activity
T1078 - Valid Accounts
  • 1 Rules
Cisco Firepower
  • app-activity
  • app-login
  • authentication-successful
  • config-change
  • dns-query
  • dns-response
  • failed-usb-activity
  • netflow-connection
  • network-connection-failed
  • network-connection-successful
  • print-activity
  • security-alert
  • vpn-login
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 40 Rules
  • 12 Models
Cisco ISE
  • account-lockout
  • app-activity
  • authentication-failed
  • computer-logon
  • nac-failed-logon
  • nac-logon
  • network-alert
  • print-activity
  • remote-logon
  • security-alert
  • vpn-login
  • vpn-logout
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Cisco Meraki MX appliances
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 9 Models
Cisco NPE
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 239 Rules
  • 33 Models
Cisco Netflow
  • netflow-connection
T1071 - Application Layer Protocol
  • 1 Rules
Cisco Secure Endpoint
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Cisco Secure Web Appliance
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Cisco TACACS
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
Cisco Umbrella
  • dns-query
  • dns-response
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1071.004 - Application Layer Protocol: DNS
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 31 Rules
  • 8 Models
Duo Access Security
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-logon
  • file-delete
  • vpn-login
  • vpn-logout
T1078 - Valid Accounts
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 3 Rules
IronPort Email
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • network-alert
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 29 Rules
  • 9 Models
IronPort Web Security
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Proxy Umbrella
  • app-activity
  • print-activity
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 29 Rules
  • 8 Models

Vendor: Citrix

ProductEvent TypesMITRE TTPContent
Citrix AppFW
  • database-query
  • network-connection-successful
T1071 - Application Layer Protocol
  • 1 Rules
Citrix Endpoint Management
  • privileged-access
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
Citrix Netscaler
  • app-login
  • authentication-successful
  • database-access
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 31 Rules
  • 10 Models
Citrix Netscaler VPN
  • app-login
  • authentication-failed
  • dlp-email-alert-in-failed
  • network-connection-failed
  • vpn-login
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 31 Rules
  • 8 Models
Citrix ShareFile
  • app-login
  • failed-app-login
  • file-download
  • file-upload
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 7 Models
Citrix XenApp
  • app-login
  • failed-app-login
  • failed-vpn-login
T1078 - Valid Accounts
  • 1 Rules
Citrix XenDesktop
  • app-login
T1078 - Valid Accounts
  • 1 Rules
Netscaler WAF
  • network-connection-successful
  • print-activity
T1071 - Application Layer Protocol
  • 1 Rules
Web Logging
  • failed-physical-access
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models

Vendor: Clearsense

ProductEvent TypesMITRE TTPContent
Clearsense
  • app-login
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: Cloud Application

ProductEvent TypesMITRE TTPContent
Cloud Application
  • app-activity
  • app-login
  • failed-app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Cloudflare

ProductEvent TypesMITRE TTPContent
Cloudflare CDN
  • app-activity
T1078 - Valid Accounts
  • 1 Rules
Cloudflare Insights
  • app-login
  • member-added
  • member-removed
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Cloudflare WAF
  • app-activity
  • network-connection-successful
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 8 Models

Vendor: Code42

ProductEvent TypesMITRE TTPContent
Code42 Incydr
  • dlp-email-alert-out
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • usb-insert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models

Vendor: Cofense

ProductEvent TypesMITRE TTPContent
Phishme
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
ProductEvent TypesMITRE TTPContent
Cognitas CrossLink
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: CrowdStrike

ProductEvent TypesMITRE TTPContent
Falcon
  • app-activity
  • app-activity-failed
  • app-login
  • authentication-failed
  • batch-logon
  • computer-logon
  • dlp-alert
  • dlp-email-alert-out-failed
  • failed-app-login
  • file-alert
  • file-delete
  • file-download
  • file-read
  • file-write
  • local-logon
  • network-connection-failed
  • network-connection-successful
  • process-alert
  • process-created
  • process-network
  • remote-access
  • remote-logon
  • security-alert
  • service-logon
  • usb-activity
  • usb-insert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 256 Rules
  • 42 Models

Vendor: CyberArk

ProductEvent TypesMITRE TTPContent
CyberArk Endpoint Privilege Management
  • file-delete
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models
CyberArk Vault
  • account-password-change
  • account-password-change-failed
  • account-password-reset
  • account-switch
  • app-activity
  • app-activity-failed
  • app-login
  • computer-logon
  • failed-app-login
  • failed-logon
  • file-delete
  • file-read
  • file-write
  • process-created
  • remote-logon
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 247 Rules
  • 35 Models
Privileged Session Manager
  • app-activity
  • app-login
  • file-permission-change
T1078 - Valid Accounts
  • 1 Rules
Privileged Threat Analytics
  • failed-logon
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules

Vendor: Damballa

ProductEvent TypesMITRE TTPContent
Failsafe
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Darktrace

ProductEvent TypesMITRE TTPContent
Darktrace
  • app-login
  • dlp-email-alert-in-failed
T1078 - Valid Accounts
  • 1 Rules
Darktrace Enterprise Immune System
  • dlp-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Dell

ProductEvent TypesMITRE TTPContent
EMC Isilon
  • app-activity
  • file-delete
  • file-permission-change
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models
One Identity Manager
  • account-password-change
  • account-switch
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
RSA Authentication Manager
  • app-activity
  • app-login
  • authentication-failed
  • authentication-successful
  • dlp-alert
  • failed-vpn-login
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
SonicWALL Aventail
  • nac-failed-logon
  • vpn-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Digital Arts

ProductEvent TypesMITRE TTPContent
Digital Arts i-FILTER for Business
  • security-alert
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 12 Models

Vendor: Digital Guardian

ProductEvent TypesMITRE TTPContent
Digital Guardian Endpoint Protection
  • app-login
  • dlp-email-alert-out
  • failed-app-login
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • local-logon
  • network-connection-failed
  • network-connection-successful
  • print-activity
  • usb-insert
  • vpn-connection
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 10 Rules
  • 4 Models
Digital Guardian Network DLP
  • dlp-alert
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Dropbox

ProductEvent TypesMITRE TTPContent
Dropbox
  • app-activity
  • app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-write
  • network-connection-failed
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 9 Rules
  • 3 Models

Vendor: Dtex Systems

ProductEvent TypesMITRE TTPContent
DTEX InTERCEPT
  • file-delete
  • file-read
  • file-write
  • local-logon
  • print-activity
  • process-created
  • remote-logon
  • usb-write
  • workstation-locked
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 245 Rules
  • 35 Models

Vendor: EMP

ProductEvent TypesMITRE TTPContent
EMP
  • app-activity
  • dlp-email-alert-in-failed
T1078 - Valid Accounts
  • 1 Rules

Vendor: ESET

ProductEvent TypesMITRE TTPContent
ESET Endpoint Security
  • app-login
  • authentication-successful
  • failed-ds-access
  • failed-logon
  • network-alert
  • security-alert
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 34 Rules
  • 11 Models

Vendor: ESector

ProductEvent TypesMITRE TTPContent
ESector DEFESA
  • file-read
  • file-write
  • web-activity-denied
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 33 Rules
  • 10 Models

Vendor: EdgeWave

ProductEvent TypesMITRE TTPContent
EdgeWave iPrism
  • security-alert
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 12 Models

Vendor: Egnyte

ProductEvent TypesMITRE TTPContent
Egnyte
  • account-password-reset
  • app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-upload
  • file-write
  • remote-logon
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 8 Rules
  • 4 Models

Vendor: EnSilo

ProductEvent TypesMITRE TTPContent
EnSilo
  • remote-access
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: EndPoint

ProductEvent TypesMITRE TTPContent
EndPoint
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Entrust

ProductEvent TypesMITRE TTPContent
IdentityGuard
  • authentication-failed
  • authentication-successful
  • computer-logon
T1078 - Valid Accounts
  • 1 Rules

Vendor: Epic

ProductEvent TypesMITRE TTPContent
Epic SIEM
  • account-password-change
  • app-activity
  • app-login
  • authentication-successful
  • failed-app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Exabeam

ProductEvent TypesMITRE TTPContent
Exabeam Advanced Analytics
  • app-activity
T1078 - Valid Accounts
  • 1 Rules
Exabeam DL
  • account-password-change
  • app-activity
  • app-login
  • dlp-alert
  • failed-app-login
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: Extrahop

ProductEvent TypesMITRE TTPContent
Reveal(x)
  • authentication-successful
  • dns-query
  • network-alert
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 2 Models

Vendor: F5

ProductEvent TypesMITRE TTPContent
BIG-IP DNS
  • dns-query
  • vpn-logout
T1071.004 - Application Layer Protocol: DNS
  • 1 Rules
F5 Advanced Web Application Firewall (WAF)
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • network-connection-successful
  • print-activity
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 240 Rules
  • 33 Models
F5 BIG-IP
  • app-activity
  • failed-vpn-login
  • print-activity
  • process-alert
  • remote-logon
  • vpn-login
T1078 - Valid Accounts
T1204 - User Execution
  • 21 Rules
  • 10 Models
F5 BIG-IP Access Policy Manager (APM)
  • app-activity
  • authentication-failed
  • authentication-successful
  • process-alert
  • vpn-login
  • vpn-logout
T1078 - Valid Accounts
T1204 - User Execution
  • 20 Rules
  • 9 Models
F5 BIG-IP Advanced Firewall Module (AFM)
  • app-activity
  • network-connection-successful
T1071 - Application Layer Protocol
T1078 - Valid Accounts
  • 2 Rules
F5 BIG-IP Application Security Manager (ASM)
  • app-activity
  • authentication-failed
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 29 Rules
  • 8 Models
F5 Silverline
  • dlp-email-alert-in-failed
  • network-connection-failed
T1071 - Application Layer Protocol
  • 2 Rules
WebSafe
  • app-login
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 29 Rules
  • 8 Models

Vendor: FTP

ProductEvent TypesMITRE TTPContent
FTP
  • app-activity
  • app-activity-failed
  • app-login
  • failed-app-login
  • file-delete
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models

Vendor: Fidelis

ProductEvent TypesMITRE TTPContent
Fidelis Network
  • failed-logon
  • failed-physical-access
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules
Fidelis XPS
  • dlp-email-alert-in
  • failed-physical-access
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: FileAuditor

ProductEvent TypesMITRE TTPContent
FileAuditor
  • failed-app-login
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models

Vendor: FireEye

ProductEvent TypesMITRE TTPContent
FireEye Email Gateway
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
FireEye Endpoint Security (CM)
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
FireEye Endpoint Security (HX)
  • file-write
  • process-alert
  • security-alert
  • web-activity-denied
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 53 Rules
  • 20 Models
FireEye Helix
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
FireEye Network Security (Helix)
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
FireEye Network Security (NX)
  • network-alert
  • security-alert
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 12 Models

Vendor: Forcepoint

ProductEvent TypesMITRE TTPContent
Forcepoint CASB
  • account-password-change
  • app-activity
  • failed-app-login
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Forcepoint DLP
  • authentication-failed
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • usb-insert
T1204 - User Execution
  • 2 Rules
  • 2 Models
Forcepoint NGFW
  • app-login
  • network-connection-successful
T1071 - Application Layer Protocol
T1078 - Valid Accounts
  • 2 Rules
Websense ESG
  • dns-query
T1071.004 - Application Layer Protocol: DNS
  • 1 Rules
Websense Secure Gateway
  • nac-failed-logon
  • network-connection-failed
  • usb-insert
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 8 Models

Vendor: Forescout

ProductEvent TypesMITRE TTPContent
EyeInspect
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 27 Rules
  • 7 Models
Forescout CounterACT
  • app-activity
  • network-alert
  • network-connection-failed
  • network-connection-successful
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 2 Models

Vendor: Fortinet

ProductEvent TypesMITRE TTPContent
FortiAuthenticator
  • authentication-successful
  • vpn-logout
T1078 - Valid Accounts
  • 1 Rules
Fortinet Enterprise Firewall
  • app-activity
  • computer-logon
  • failed-app-login
  • file-write
  • network-connection-successful
  • security-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 11 Rules
  • 6 Models
Fortinet FortiWeb
  • dlp-email-alert-out-failed
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models
Fortinet UTM
  • app-activity
  • authentication-successful
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • failed-app-login
  • security-alert
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 35 Rules
  • 12 Models
Fortinet VPN
  • failed-vpn-login
  • vpn-login
  • vpn-logout
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 7 Models

Vendor: GTB

ProductEvent TypesMITRE TTPContent
GTBInspector
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: Gamma

ProductEvent TypesMITRE TTPContent
Gamma
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Gemalto

ProductEvent TypesMITRE TTPContent
Gemalto MFA
  • authentication-successful
  • dlp-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: GitHub

ProductEvent TypesMITRE TTPContent
GitHub
  • app-activity
  • app-activity-failed
  • app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: GoAnywhere

ProductEvent TypesMITRE TTPContent
GoAnywhere MFT
  • dlp-email-alert-out-failed
  • failed-logon
  • file-delete
  • file-download
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 5 Rules
  • 2 Models

Vendor: Google

ProductEvent TypesMITRE TTPContent
Cloud IDS
  • app-activity
T1078 - Valid Accounts
  • 1 Rules
GCP Squid Proxy
  • security-alert
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 12 Models
Gmail
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • vpn-login
T1078 - Valid Accounts
  • 1 Rules
Google
  • app-activity
  • app-login
  • failed-app-login
T1078 - Valid Accounts
  • 1 Rules
Google Calendar
  • app-login
T1078 - Valid Accounts
  • 1 Rules
Google Drive
  • app-activity
  • file-delete
  • file-permission-change
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models
Virtual Private Cloud
  • netflow-connection
T1071 - Application Layer Protocol
  • 1 Rules

Vendor: HP

ProductEvent TypesMITRE TTPContent
Aruba ClearPass Access Control and Policy Management
  • account-password-reset
  • computer-logon
  • nac-logon
  • network-connection-failed
  • vpn-connection
T1071 - Application Layer Protocol
  • 2 Rules
Aruba Mobility Master
  • local-logon
  • nac-failed-logon
  • nac-logon
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
Aruba Wireless controller
  • account-password-reset
  • computer-logon
  • nac-failed-logon
  • nac-logon
  • network-connection-failed
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 241 Rules
  • 33 Models
HP Comware
  • failed-logon
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules
HP SafeCom
  • dlp-email-alert-in
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models
Print Server
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: HashiCorp

ProductEvent TypesMITRE TTPContent
HashiCorp Vault
  • account-password-reset
  • privileged-object-access
T1204 - User Execution
  • 2 Rules
  • 2 Models
Terraform
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models

Vendor: HelpSystems

ProductEvent TypesMITRE TTPContent
Powertech Identity Access Manager (BoKs)
  • account-switch
  • file-delete
  • file-read
  • file-write
  • local-logon
  • remote-logon
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 8 Rules
  • 4 Models

Vendor: Hornet

ProductEvent TypesMITRE TTPContent
Hornet Email
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • privileged-access
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Huawei

ProductEvent TypesMITRE TTPContent
Enterprise Network Firewall
  • database-query
  • network-connection-successful
T1071 - Application Layer Protocol
  • 1 Rules
Unified Security Gateway
  • authentication-successful
  • network-alert
  • network-connection-failed
  • vpn-login
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 2 Models

Vendor: IBM

ProductEvent TypesMITRE TTPContent
IBM DB2
  • authentication-failed
  • failed-physical-access
  • file-read
  • remote-logon
T1027 - Obfuscated Files or Information
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 3 Models
IBM Endpoint Manager
  • network-connection-failed
T1071 - Application Layer Protocol
  • 2 Rules
IBM Lotus Notes
  • file-upload
  • network-connection-successful
T1071 - Application Layer Protocol
  • 1 Rules
IBM Racf
  • app-login
  • authentication-successful
  • database-access
  • failed-app-login
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 7 Models
IBM Sametime
  • app-login
  • dlp-email-alert-out-failed
T1078 - Valid Accounts
  • 1 Rules
IBM Security Access Manager
  • usb-insert
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models
IBM Sterling B2B Integrator
  • app-activity
  • failed-logon
  • member-added
  • member-removed
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 5 Rules
  • 2 Models
Infosphere Guardium
  • database-alert
  • database-login
  • network-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 6 Rules
  • 4 Models
Lotus Mobile Connect
  • authentication-failed
  • authentication-successful
  • vpn-login
T1078 - Valid Accounts
  • 1 Rules
Proventia Network IPS
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: ICPAM

ProductEvent TypesMITRE TTPContent
ICPAM
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: IMSS

ProductEvent TypesMITRE TTPContent
IMSS
  • dlp-alert
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: IMSVA

ProductEvent TypesMITRE TTPContent
IMSVA
  • dlp-email-alert-in
  • dlp-email-alert-out
  • network-connection-failed
T1071 - Application Layer Protocol
  • 2 Rules

Vendor: IPTables

ProductEvent TypesMITRE TTPContent
IPTables
  • network-connection-successful
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 7 Models

Vendor: IXIA

ProductEvent TypesMITRE TTPContent
IXIA ThreatArmor
  • app-activity
  • network-connection-failed
T1071 - Application Layer Protocol
T1078 - Valid Accounts
  • 3 Rules

Vendor: Illumio

ProductEvent TypesMITRE TTPContent
Illumio
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: Imperva

ProductEvent TypesMITRE TTPContent
CounterBreach
  • database-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 3 Models
Imperva File Activity Monitoring (FAM)
  • file-delete
  • file-read
  • file-write
  • print-activity
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models
Imperva SecureSphere
  • app-login
  • database-alert
  • database-delete
  • database-failed-login
  • database-login
  • database-query
  • database-update
  • network-alert
  • print-activity
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 9 Rules
  • 6 Models
Incapsula
  • authentication-failed
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models

Vendor: Imprivata

ProductEvent TypesMITRE TTPContent
Imprivata
  • app-activity
  • app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: InfoWatch

ProductEvent TypesMITRE TTPContent
InfoWatch
  • app-login
  • dlp-email-alert-in
  • dlp-email-alert-out
  • file-permission-change
  • print-activity
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 29 Rules
  • 8 Models

Vendor: Infoblox

ProductEvent TypesMITRE TTPContent
BloxOne
  • computer-logon
  • dlp-email-alert-out-failed
  • network-connection-failed
  • network-connection-successful
  • process-created
  • security-alert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 244 Rules
  • 36 Models

Vendor: Ipswitch

ProductEvent TypesMITRE TTPContent
IPswitch MoveIt
  • app-activity
  • app-login
  • failed-app-login
  • file-download
  • file-read
T1027 - Obfuscated Files or Information
T1078 - Valid Accounts
  • 2 Rules
  • 1 Models
MoveIt DMZ
  • account-password-change
  • authentication-failed
  • failed-logon
  • file-delete
  • file-download
  • file-upload
  • file-write
  • member-added
  • process-created-failed
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1070.005 - T1070.005
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
  • 13 Rules
  • 5 Models

Vendor: IronNet

ProductEvent TypesMITRE TTPContent
IronDefense
  • failed-logon
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 2 Rules

Vendor: JH

ProductEvent TypesMITRE TTPContent
JH
  • network-connection-failed
T1071 - Application Layer Protocol
  • 2 Rules

Vendor: Johnson Controls

ProductEvent TypesMITRE TTPContent
Johnson Controls P2000
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Juniper Networks

ProductEvent TypesMITRE TTPContent
Juniper Networks
  • account-deleted
  • network-connection-successful
T1071 - Application Layer Protocol
  • 1 Rules
Juniper Networks Pulse Secure
  • app-activity
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • failed-vpn-login
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1071 - Application Layer Protocol
T1078 - Valid Accounts
  • 2 Rules
Juniper SRX
  • authentication-successful
  • config-change
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • security-alert
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 37 Rules
  • 12 Models
Juniper VPN
  • app-activity
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • security-alert
  • vpn-login
  • vpn-logout
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: KABA EXOS

ProductEvent TypesMITRE TTPContent
KABA EXOS
  • file-read
T1027 - Obfuscated Files or Information
  • 1 Rules
  • 1 Models

Vendor: Kaspersky

ProductEvent TypesMITRE TTPContent
Kaspersky AV
  • app-activity
  • file-alert
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Kaspersky Endpoint Security for Business
  • file-alert
  • network-alert
  • security-alert
  • usb-insert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Kemp

ProductEvent TypesMITRE TTPContent
Kemp LoadMaster
  • app-activity
  • remote-logon
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Load Balancer
  • failed-app-login
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: LEAP

ProductEvent TypesMITRE TTPContent
LEAP
  • app-activity
  • file-download
T1078 - Valid Accounts
  • 1 Rules

Vendor: LOGBinder

ProductEvent TypesMITRE TTPContent
SharePoint
  • config-change
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models

Vendor: LanScope

ProductEvent TypesMITRE TTPContent
LanScope Cat
  • app-activity
  • dlp-alert
  • failed-usb-activity
  • file-write
  • local-logon
  • print-activity
  • process-created
  • process-created-failed
  • process-network
  • usb-activity
  • usb-write
  • web-activity-allowed
  • workstation-locked
  • workstation-unlocked
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 280 Rules
  • 46 Models

Vendor: LastPass

ProductEvent TypesMITRE TTPContent
LastPass
  • app-activity
  • app-login
  • failed-app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Lastline

ProductEvent TypesMITRE TTPContent
Lastline
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Lenel

ProductEvent TypesMITRE TTPContent
OnGuard
  • failed-physical-access
  • physical-access
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Linux

ProductEvent TypesMITRE TTPContent
Linux CentOs
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 27 Rules
  • 7 Models
SSH
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: LogMeIn

ProductEvent TypesMITRE TTPContent
RemotelyAnywhere
  • app-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: LogRhythm

ProductEvent TypesMITRE TTPContent
LogRhythm
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 27 Rules
  • 7 Models

Vendor: Lumension

ProductEvent TypesMITRE TTPContent
Lumension
  • failed-usb-activity
  • usb-activity
  • usb-insert
  • usb-read
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Lyrix

ProductEvent TypesMITRE TTPContent
Lyrix
  • app-activity
  • physical-access
T1078 - Valid Accounts
  • 1 Rules

Vendor: Malwarebytes

ProductEvent TypesMITRE TTPContent
Malwarebytes Endpoint Protection
  • process-alert
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 22 Rules
  • 12 Models
Malwarebytes Incident Response
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: MasterSAM

ProductEvent TypesMITRE TTPContent
MasterSAM PAM
  • authentication-failed
  • authentication-successful
  • failed-physical-access
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: McAfee

ProductEvent TypesMITRE TTPContent
McAfee DLP
  • dlp-alert
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • print-activity
  • security-alert
  • usb-insert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
McAfee Email Protection
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
T1204 - User Execution
  • 2 Rules
  • 2 Models
McAfee Endpoint Security
  • dlp-alert
  • dlp-email-alert-in-failed
  • file-write
  • local-logon
  • network-alert
  • process-alert
  • security-alert
  • usb-insert
  • usb-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 26 Rules
  • 13 Models
McAfee Enterprise Security Manager
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
McAfee NSM
  • app-login
  • dlp-alert
  • file-delete
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
McAfee Network Security Platform (IPS)
  • dlp-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models
McAfee Solidifier
  • local-logon
T1204 - User Execution
  • 2 Rules
  • 2 Models
McAfee Web Gateway
  • alert-iot
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
  • 31 Rules
  • 9 Models
Skyhigh Networks CASB
  • account-creation
  • app-activity
  • app-login
  • dlp-alert
  • failed-app-login
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: Microsoft

ProductEvent TypesMITRE TTPContent
Advanced Threat Analytics (ATA)
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 239 Rules
  • 33 Models
Advanced Threat Protection
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
AppLocker
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Azure
  • account-password-change
  • account-password-reset
  • app-activity
  • app-activity-failed
  • app-login
  • authentication-failed
  • authentication-successful
  • cloud-admin-activity
  • cloud-admin-activity-failed
  • database-query
  • dlp-email-alert-in-failed
  • dns-response
  • failed-app-login
  • failed-logon
  • failed-usb-activity
  • file-delete
  • file-download
  • file-read
  • file-write
  • member-added
  • member-removed
  • network-connection-failed
  • network-connection-successful
  • privileged-access
  • process-created
  • security-alert
  • storage-activity
  • storage-activity-failed
  • usb-activity
  • usb-insert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 253 Rules
  • 37 Models
Azure AD Identity Protection
  • remote-access
T1204 - User Execution
  • 2 Rules
  • 2 Models
Azure Active Directory
  • account-password-change
  • account-unlocked
  • app-activity
  • app-activity-failed
  • app-login
  • dlp-email-alert-out
  • failed-app-login
  • member-added
  • process-created
  • security-alert
  • usb-insert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 243 Rules
  • 36 Models
Azure Advanced Threat Protection
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Azure MFA
  • account-password-reset
  • authentication-successful
T1078 - Valid Accounts
  • 1 Rules
Azure Security Center
  • app-activity-failed
  • dlp-email-alert-out-failed
  • process-alert
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 22 Rules
  • 12 Models
Cloud App Security (MCAS)
  • account-password-change
  • app-activity
  • app-activity-failed
  • app-login
  • failed-app-login
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • security-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 10 Rules
  • 6 Models
Defender ATP
  • app-login
  • batch-logon
  • file-delete
  • file-write
  • local-logon
  • member-removed
  • network-alert
  • process-alert
  • process-created
  • process-network
  • process-network-failed
  • remote-access
  • remote-logon
  • security-alert
  • usb-write
  • web-activity-denied
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 282 Rules
  • 49 Models
Defender Antivirus
  • file-alert
T1204 - User Execution
  • 1 Rules
  • 1 Models
DirectAccess
  • security-alert
  • vpn-login
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Exchange
  • app-activity
  • app-activity-failed
  • app-login
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-app-login
  • member-removed
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
IIS
  • network-connection-failed
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Office 365
  • account-disabled
  • app-activity
  • app-activity-failed
  • app-login
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-app-login
  • failed-logon
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • ntlm-logon
  • process-created
  • remote-logon
  • security-alert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 249 Rules
  • 37 Models
OneDrive
  • app-activity
  • file-read
  • file-upload
  • local-logon
T1027 - Obfuscated Files or Information
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 3 Models
Routing and Remote Access Service
  • authentication-successful
  • vpn-login
T1078 - Valid Accounts
  • 1 Rules
SQL Server
  • database-access
  • database-failed-login
  • database-login
  • database-query
  • failed-app-login
  • file-read
  • web-activity-denied
T1027 - Obfuscated Files or Information
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models
Sysmon
  • app-activity
  • dns-response
  • file-delete
  • process-created
  • process-network
  • web-activity-denied
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 276 Rules
  • 43 Models
Web Application Proxy
  • failed-logon
  • network-connection-failed
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 8 Models
Web Application Proxy-TLS Gateway
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Windows
  • account-creation
  • account-deleted
  • account-disabled
  • account-enabled
  • account-lockout
  • account-password-change
  • account-password-reset
  • account-switch
  • account-unlocked
  • app-activity
  • app-login
  • audit-log-clear
  • audit-policy-change
  • authentication-failed
  • authentication-successful
  • computer-logon
  • database-query
  • dcom-activation-failed
  • dlp-alert
  • dlp-email-alert-out-failed
  • dns-query
  • dns-response
  • ds-access
  • failed-app-login
  • failed-logon
  • failed-vpn-login
  • file-close
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • local-logon
  • logout-remote
  • member-added
  • member-removed
  • nac-logon
  • netflow-connection
  • network-alert
  • network-connection-failed
  • privileged-access
  • privileged-object-access
  • process-created
  • process-network
  • process-network-failed
  • remote-access
  • remote-logon
  • security-alert
  • service-created
  • service-logon
  • share-access
  • task-created
  • usb-activity
  • usb-write
  • vpn-login
  • vpn-logout
  • web-activity-denied
  • winsession-disconnect
  • workstation-locked
  • workstation-unlocked
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1207 - Rogue Domain Controller
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1569.002 - T1569.002
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 327 Rules
  • 68 Models
Windows DNSServer
  • dns-query
T1071.004 - Application Layer Protocol: DNS
  • 1 Rules
Windows Defender
  • computer-logon
  • file-alert
  • process-created
  • security-alert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 241 Rules
  • 35 Models

Vendor: Mimecast

ProductEvent TypesMITRE TTPContent
Mimecast Email Security
  • account-password-reset
  • app-activity
  • app-login
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • failed-app-login
  • network-alert
  • process-alert
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 47 Rules
  • 16 Models
Targeted Threat Protection - URL
  • physical-access
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models

Vendor: MobileIron

ProductEvent TypesMITRE TTPContent
MobileIron
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Morphisec

ProductEvent TypesMITRE TTPContent
Morphisec EPTP
  • app-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: N3K

ProductEvent TypesMITRE TTPContent
N3K
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: NCP

ProductEvent TypesMITRE TTPContent
NCP
  • authentication-successful
  • vpn-login
  • vpn-logout
T1078 - Valid Accounts
  • 1 Rules

Vendor: NNT

ProductEvent TypesMITRE TTPContent
NNT ChangeTracker
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Namespace rDirectory

ProductEvent TypesMITRE TTPContent
Namespace rDirectory
  • account-deleted
  • account-disabled
  • account-enabled
  • account-password-change-failed
  • app-login
  • member-added
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: Nasuni

ProductEvent TypesMITRE TTPContent
Nasuni
  • authentication-failed
  • file-delete
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models

Vendor: NetApp

ProductEvent TypesMITRE TTPContent
NetApp
  • app-activity
  • file-delete
  • file-read
  • security-alert
T1027 - Obfuscated Files or Information
T1078 - Valid Accounts
T1204 - User Execution
  • 6 Rules
  • 5 Models

Vendor: NetDocs

ProductEvent TypesMITRE TTPContent
NetDocs
  • app-activity
  • authentication-failed
  • failed-app-login
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models

Vendor: NetIQ

ProductEvent TypesMITRE TTPContent
NetIQ
  • app-login
  • failed-physical-access
T1078 - Valid Accounts
  • 1 Rules

Vendor: NetMotion Wireless

ProductEvent TypesMITRE TTPContent
NetMotion Wireless
  • nac-logon
  • vpn-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Netskope

ProductEvent TypesMITRE TTPContent
Netskope Security Cloud
  • app-activity
  • app-login
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • failed-app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • network-connection-failed
  • network-connection-successful
  • process-created
  • security-alert
  • web-activity-allowed
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 277 Rules
  • 45 Models

Vendor: Netwrix

ProductEvent TypesMITRE TTPContent
Netwrix Auditor
  • account-disabled
  • account-lockout
  • account-password-reset
  • account-unlocked
  • app-activity
  • app-login
  • database-access
  • database-failed-login
  • dns-query
  • ds-access
  • file-write
  • member-added
  • member-removed
  • nac-logon
  • security-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1204 - User Execution
T1207 - Rogue Domain Controller
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 12 Rules
  • 6 Models

Vendor: Nexthink

ProductEvent TypesMITRE TTPContent
Nexthink
  • task-created
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1112 - Modify Registry
T1204 - User Execution
  • 11 Rules
  • 8 Models

Vendor: Nokia VitalQIP

ProductEvent TypesMITRE TTPContent
Nokia VitalQIP
  • app-login
  • computer-logon
T1078 - Valid Accounts
  • 1 Rules

Vendor: Nortel Contivity

ProductEvent TypesMITRE TTPContent
Nortel Contivity VPN
  • computer-logon
  • vpn-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Novell

ProductEvent TypesMITRE TTPContent
eDirectory
  • account-disabled
  • account-enabled
  • account-password-change
  • account-unlocked
  • app-activity
  • authentication-failed
  • authentication-successful
T1078 - Valid Accounts
  • 1 Rules

Vendor: ObserveIT

ProductEvent TypesMITRE TTPContent
ObserveIT
  • app-activity
  • app-login
  • dlp-alert
  • failed-app-login
  • member-added
  • process-created
  • remote-logon
  • security-alert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 242 Rules
  • 35 Models

Vendor: Okta

ProductEvent TypesMITRE TTPContent
Okta Adaptive MFA
  • account-creation
  • account-enabled
  • account-lockout
  • app-activity
  • app-activity-failed
  • app-login
  • authentication-failed
  • failed-app-login
  • failed-logon
  • nac-logon
  • network-alert
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 7 Rules
  • 4 Models

Vendor: Onapsis

ProductEvent TypesMITRE TTPContent
Onapsis
  • app-login
  • dns-query
  • security-alert
  • vpn-logout
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1204 - User Execution
  • 6 Rules
  • 4 Models

Vendor: OneLogin

ProductEvent TypesMITRE TTPContent
OneLogin
  • app-login
  • failed-app-login
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: OneSpan

ProductEvent TypesMITRE TTPContent
Digipass
  • account-password-reset
  • app-login
  • nac-logon
T1078 - Valid Accounts
  • 1 Rules
OneSpan
  • authentication-successful
T1078 - Valid Accounts
  • 1 Rules

Vendor: OpenDJ

ProductEvent TypesMITRE TTPContent
OpenDJ LDAP
  • authentication-failed
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Oracle

ProductEvent TypesMITRE TTPContent
Access Manager
  • app-activity
  • app-login
  • authentication-successful
  • failed-app-login
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 1 Rules
Oracle Database
  • database-access
  • database-failed-login
  • database-login
  • database-query
  • database-update
  • failed-physical-access
  • local-logon
T1204 - User Execution
  • 2 Rules
  • 2 Models
Solaris
  • computer-logon
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 239 Rules
  • 33 Models

Vendor: Ordr

ProductEvent TypesMITRE TTPContent
Ordr SCE
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models

Vendor: Osirium

ProductEvent TypesMITRE TTPContent
Osirium
  • app-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: Palo Alto Networks

ProductEvent TypesMITRE TTPContent
Cortex XDR
  • app-login
  • authentication-failed
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
GlobalProtect
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • network-alert
  • physical-access
  • remote-logon
  • security-alert
  • vpn-login
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Magnifier
  • remote-access
T1204 - User Execution
  • 2 Rules
  • 2 Models
NGFW
  • account-password-change
  • app-activity
  • authentication-successful
  • config-change
  • dlp-email-alert-out
  • file-alert
  • local-logon
  • network-connection-successful
  • security-alert
  • vpn-login
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 36 Rules
  • 12 Models
Palo Alto Aperture
  • app-login
  • dlp-email-alert-out
  • file-delete
  • file-read
  • file-write
  • network-alert
  • security-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 10 Rules
  • 6 Models
Prisma Cloud
  • app-login
T1078 - Valid Accounts
  • 1 Rules
Traps
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
WildFire
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Password Manager Pro

ProductEvent TypesMITRE TTPContent
Password Manager Pro
  • account-switch
  • failed-app-login
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Paxton

ProductEvent TypesMITRE TTPContent
NET2DOOR
  • netflow-connection
  • physical-access
T1071 - Application Layer Protocol
  • 1 Rules

Vendor: Phantom

ProductEvent TypesMITRE TTPContent
Phantom
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Ping Identity

ProductEvent TypesMITRE TTPContent
Ping Identity
  • app-activity
  • app-activity-failed
  • app-login
  • authentication-failed
  • authentication-successful
  • dlp-email-alert-in-failed
  • failed-app-login
  • service-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
PingID
  • account-password-change
  • account-password-change-failed
  • authentication-failed
  • authentication-successful
  • dlp-email-alert-in-failed
T1078 - Valid Accounts
  • 1 Rules
PingOne
  • app-login
  • dns-response
  • network-alert
  • service-logon
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1204 - User Execution
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 5 Rules
  • 2 Models

Vendor: Portnox

ProductEvent TypesMITRE TTPContent
Portnox CLEAR
  • nac-logon
  • registry-write
T1112 - Modify Registry
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 2 Rules
  • 1 Models

Vendor: PostScript

ProductEvent TypesMITRE TTPContent
PostScript
  • app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: PostgreSQL

ProductEvent TypesMITRE TTPContent
PostgreSQL
  • database-access
  • database-login
  • database-query
  • file-read
  • security-alert
T1027 - Obfuscated Files or Information
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 5 Models

Vendor: PowerSentry

ProductEvent TypesMITRE TTPContent
PowerSentry
  • app-login
  • failed-app-login
  • network-connection-failed
T1071 - Application Layer Protocol
T1078 - Valid Accounts
  • 3 Rules

Vendor: Procad

ProductEvent TypesMITRE TTPContent
Pro.File DMS
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Proofpoint

ProductEvent TypesMITRE TTPContent
ObserveIT
  • app-activity
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
Proofpoint CASB
  • dlp-alert
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models
Proofpoint DLP
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
T1204 - User Execution
  • 2 Rules
  • 2 Models
Proofpoint TAP/POD
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Qualys

ProductEvent TypesMITRE TTPContent
Qualys
  • network-connection-failed
T1071 - Application Layer Protocol
  • 2 Rules

Vendor: Quest Software

ProductEvent TypesMITRE TTPContent
Change Auditor
  • account-lockout
  • account-unlocked
  • ds-access
  • failed-app-login
  • file-delete
  • file-write
  • local-logon
  • member-added
  • member-removed
  • nac-failed-logon
  • physical-access
  • remote-logon
  • security-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1207 - Rogue Domain Controller
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 11 Rules
  • 6 Models

Vendor: RS2

ProductEvent TypesMITRE TTPContent
RS2
  • app-login
  • physical-access
T1078 - Valid Accounts
  • 1 Rules

Vendor: RSA

ProductEvent TypesMITRE TTPContent
RSA
  • app-activity
T1078 - Valid Accounts
  • 1 Rules
RSA DLP
  • dlp-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models
SecurID
  • authentication-successful
  • dlp-email-alert-in
  • task-created
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1078 - Valid Accounts
T1112 - Modify Registry
T1204 - User Execution
  • 12 Rules
  • 8 Models

Vendor: Radius

ProductEvent TypesMITRE TTPContent
Radius
  • authentication-successful
  • nac-logon
  • vpn-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: RangerAudit

ProductEvent TypesMITRE TTPContent
RangerAudit
  • app-activity
  • app-login
  • database-activity-failed
  • database-query
  • dlp-alert
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 8 Rules
  • 4 Models

Vendor: Rapid7

ProductEvent TypesMITRE TTPContent
InsightVM
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 239 Rules
  • 33 Models
Nexpose
  • process-created
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 239 Rules
  • 33 Models

Vendor: Red Canary

ProductEvent TypesMITRE TTPContent
Red Canary
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 27 Rules
  • 7 Models

Vendor: Ricoh

ProductEvent TypesMITRE TTPContent
Ricoh
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: SAP

ProductEvent TypesMITRE TTPContent
SAP
  • account-creation
  • account-deleted
  • account-lockout
  • account-unlocked
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • file-download
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: SFTP

ProductEvent TypesMITRE TTPContent
SFTP
  • app-activity
  • app-login
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models

Vendor: SIGSCI

ProductEvent TypesMITRE TTPContent
SIGSCI
  • file-download
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models

Vendor: SSL Open VPN

ProductEvent TypesMITRE TTPContent
SSL Open VPN
  • app-activity
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • failed-vpn-login
  • network-alert
  • vpn-login
  • vpn-logout
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: Safend

ProductEvent TypesMITRE TTPContent
Data Protection Suite (DPS)
  • dlp-email-alert-in
  • usb-write
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Sailpoint

ProductEvent TypesMITRE TTPContent
FAM
  • account-lockout
  • file-delete
  • file-read
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models
IdentityNow
  • account-password-change
  • account-password-change-failed
  • app-activity
  • app-login
  • authentication-successful
  • vpn-logout
T1078 - Valid Accounts
  • 1 Rules
SecurityIQ
  • account-creation
  • account-deleted
  • account-lockout
  • account-password-reset
  • dlp-email-alert-in-failed
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • member-added
  • member-removed
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models

Vendor: Salesforce

ProductEvent TypesMITRE TTPContent
Salesforce
  • account-password-change
  • app-activity
  • app-login
  • failed-app-login
  • file-upload
T1078 - Valid Accounts
  • 1 Rules

Vendor: Sangfor

ProductEvent TypesMITRE TTPContent
NGAF
  • network-alert
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 10 Models

Vendor: Seclore

ProductEvent TypesMITRE TTPContent
Seclore
  • file-read
  • file-write
  • share-access
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 6 Rules
  • 3 Models

Vendor: Secure Computing

ProductEvent TypesMITRE TTPContent
Secure Computing SafeWord
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: Secure Envoy

ProductEvent TypesMITRE TTPContent
Secure Envoy
  • authentication-successful
  • network-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: SecureAuth

ProductEvent TypesMITRE TTPContent
SecureAuth Login
  • authentication-failed
  • authentication-successful
T1078 - Valid Accounts
  • 1 Rules
ProductEvent TypesMITRE TTPContent
SecureLink
  • app-login
  • file-download
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: SecureNet

ProductEvent TypesMITRE TTPContent
SecureNet
  • failed-app-login
  • vpn-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: SecureWorks

ProductEvent TypesMITRE TTPContent
iSensor IPS
  • network-connection-failed
T1071 - Application Layer Protocol
  • 2 Rules

Vendor: SecurityExpert

ProductEvent TypesMITRE TTPContent
SecurityExpert
  • network-connection-successful
T1071 - Application Layer Protocol
  • 1 Rules

Vendor: SentinelOne

ProductEvent TypesMITRE TTPContent
SentinelOne
  • app-activity
  • dns-query
  • dns-response
  • file-alert
  • file-delete
  • file-read
  • file-write
  • network-connection-failed
  • network-connection-successful
  • process-created
  • security-alert
  • web-activity-allowed
  • web-activity-denied
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 282 Rules
  • 45 Models

Vendor: ServiceNow

ProductEvent TypesMITRE TTPContent
ServiceNow
  • account-switch
  • app-login
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • security-alert
  • storage-access
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 10 Rules
  • 6 Models

Vendor: Shibboleth

ProductEvent TypesMITRE TTPContent
Shibboleth IdP
  • network-connection-successful
T1071 - Application Layer Protocol
  • 1 Rules
Shibboleth SSO
  • app-login
  • failed-app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Siemens

ProductEvent TypesMITRE TTPContent
Siemens
  • authentication-successful
  • failed-physical-access
  • physical-access
T1078 - Valid Accounts
  • 1 Rules

Vendor: Silverfort

ProductEvent TypesMITRE TTPContent
Silverfort
  • app-login
  • authentication-successful
  • failed-app-login
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: SiteMinder

ProductEvent TypesMITRE TTPContent
SiteMinder
  • authentication-failed
  • authentication-successful
  • database-access
T1078 - Valid Accounts
  • 1 Rules

Vendor: SkySea

ProductEvent TypesMITRE TTPContent
ClientView
  • app-activity
  • app-login
  • computer-logon
  • dlp-email-alert-out
  • dns-query
  • file-delete
  • file-read
  • file-upload
  • file-write
  • security-alert
  • usb-activity
  • web-activity-allowed
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 39 Rules
  • 14 Models

Vendor: Slack

ProductEvent TypesMITRE TTPContent
Slack
  • app-login
  • failed-vpn-login
  • file-download
  • file-upload
T1078 - Valid Accounts
  • 1 Rules

Vendor: Snort

ProductEvent TypesMITRE TTPContent
Snort
  • app-login
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: Sonicwall

ProductEvent TypesMITRE TTPContent
Sonicwall
  • failed-logon
  • failed-vpn-login
  • network-alert
  • vpn-login
  • vpn-logout
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 33 Rules
  • 10 Models

Vendor: Sophos

ProductEvent TypesMITRE TTPContent
Sophos Endpoint Protection
  • app-activity-failed
  • dlp-alert
  • failed-app-login
  • network-connection-successful
  • security-alert
  • usb-insert
  • usb-write
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 32 Rules
  • 11 Models
Sophos Firewall
  • authentication-successful
  • network-connection-successful
T1071 - Application Layer Protocol
T1078 - Valid Accounts
  • 2 Rules
Sophos SafeGuard
  • app-activity
  • database-delete
T1078 - Valid Accounts
  • 1 Rules
Sophos UTM
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Sophos XG Firewall
  • authentication-successful
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 33 Rules
  • 8 Models

Vendor: Specops

ProductEvent TypesMITRE TTPContent
Specops Password Reset
  • account-unlocked
  • network-connection-successful
T1071 - Application Layer Protocol
  • 1 Rules

Vendor: Splunk

ProductEvent TypesMITRE TTPContent
Splunk Stream
  • dlp-alert
  • dns-response
T1071.004 - Application Layer Protocol: DNS
T1204 - User Execution
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 4 Rules
  • 2 Models

Vendor: Squid

ProductEvent TypesMITRE TTPContent
Squid
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models

Vendor: StealthBits

ProductEvent TypesMITRE TTPContent
StealthIntercept
  • account-disabled
  • account-enabled
  • authentication-successful
  • ds-access
  • file-read
  • file-write
  • member-added
  • member-removed
  • network-connection-failed
  • web-activity-allowed
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1207 - Rogue Domain Controller
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 38 Rules
  • 11 Models

Vendor: Sun One

ProductEvent TypesMITRE TTPContent
LDAP
  • authentication-successful
  • usb-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: Suricata

ProductEvent TypesMITRE TTPContent
Suricata
  • app-login
T1078 - Valid Accounts
  • 1 Rules
Suricata IDS
  • app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Swivel

ProductEvent TypesMITRE TTPContent
Swivel
  • app-login
  • file-upload
  • vpn-logout
T1078 - Valid Accounts
  • 1 Rules

Vendor: Sybase

ProductEvent TypesMITRE TTPContent
Sybase
  • database-login
  • dlp-email-alert-out
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Symantec

ProductEvent TypesMITRE TTPContent
Symantec Advanced Threat Protection
  • app-activity
T1078 - Valid Accounts
  • 1 Rules
Symantec Blue Coat Content Analysis System
  • app-login
T1078 - Valid Accounts
  • 1 Rules
Symantec Blue Coat ProxySG Appliance
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Symantec Brightmail
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
T1204 - User Execution
  • 2 Rules
  • 2 Models
Symantec CloudSOC
  • app-login
  • dlp-alert
  • failed-app-login
  • file-delete
  • file-download
  • file-upload
  • usb-insert
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
Symantec Critical System Protection
  • account-switch
  • config-change
  • dlp-alert
  • failed-logon
  • local-logon
  • member-added
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 4 Rules
  • 2 Models
Symantec DLP
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • ds-access
  • failed-logon
  • security-alert
  • usb-activity
  • usb-read
  • usb-write
T1078 - Valid Accounts
T1204 - User Execution
T1207 - Rogue Domain Controller
T1210 - Exploitation of Remote Services
  • 7 Rules
  • 4 Models
Symantec EDR
  • failed-logon
  • file-alert
  • file-delete
  • file-write
  • remote-logon
  • web-activity-denied
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 37 Rules
  • 11 Models
Symantec Email Security.cloud
  • app-activity
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • process-created-failed
  • security-alert
T1070.005 - T1070.005
T1078 - Valid Accounts
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1204 - User Execution
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1220 - XSL Script Processing
  • 11 Rules
  • 7 Models
Symantec Endpoint Protection
  • authentication-successful
  • config-change
  • failed-logon
  • network-connection-failed
  • network-connection-successful
  • process-alert
  • remote-logon
  • security-alert
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 27 Rules
  • 12 Models
Symantec Endpoint Protection Mobile
  • app-login
T1078 - Valid Accounts
  • 1 Rules
Symantec Fireglass
  • failed-physical-access
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models
Symantec Managed Security Services
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models
Symantec Secure Web Gateway
  • web-activity-allowed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 30 Rules
  • 8 Models
Symantec VIP
  • app-activity
  • authentication-failed
  • authentication-successful
  • dns-query
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
  • 2 Rules
Symantec WSS
  • process-created
  • web-activity-allowed
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 267 Rules
  • 41 Models

Vendor: Tanium

ProductEvent TypesMITRE TTPContent
Endpoint Platform
  • authentication-failed
  • authentication-successful
  • file-write
  • process-created
  • security-alert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 247 Rules
  • 37 Models
Integrity Monitor
  • database-activity-failed
  • file-write
  • process-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 23 Rules
  • 10 Models

Vendor: Tenable.io

ProductEvent TypesMITRE TTPContent
Tenable.io
  • network-connection-failed
T1071 - Application Layer Protocol
  • 2 Rules

Vendor: Teradata

ProductEvent TypesMITRE TTPContent
Teradata RDBMS
  • database-login
  • dlp-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Thycotic Secret Server

ProductEvent TypesMITRE TTPContent
Thycotic Secret Server
  • account-switch
  • app-login
  • failed-app-login
  • file-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: TitanFTP

ProductEvent TypesMITRE TTPContent
TitanFTP
  • file-delete
  • file-read
  • web-activity-denied
T1027 - Obfuscated Files or Information
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models

Vendor: TrapX

ProductEvent TypesMITRE TTPContent
TrapX
  • remote-access
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: Trend Micro

ProductEvent TypesMITRE TTPContent
Apex One
  • app-login
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Cloud App Security
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models
Deep Discovery Email Inspector
  • dlp-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models
Deep Discovery Inspector
  • app-login
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
Deep Security Agent
  • network-connection-successful
  • privileged-object-access
  • security-alert
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
InterScan Web Security
  • account-password-change
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models
OfficeScan
  • account-password-change
  • dlp-alert
  • dlp-email-alert-out
  • security-alert
  • usb-insert
  • usb-read
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 31 Rules
  • 11 Models
ScanMail
  • network-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models
TippingPoint NGIPS
  • app-activity
  • database-delete
  • network-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
Trend Micro
  • network-alert
  • network-connection-successful
  • privileged-object-access
T1071 - Application Layer Protocol
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: Tripwire Enterprise

ProductEvent TypesMITRE TTPContent
Tripwire Enterprise
  • app-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: Tufin

ProductEvent TypesMITRE TTPContent
SecureTrack
  • app-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: Tyco

ProductEvent TypesMITRE TTPContent
CCURE Building Management System
  • app-activity
  • app-login
  • dns-response
  • failed-physical-access
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 3 Rules

Vendor: USB

ProductEvent TypesMITRE TTPContent
USB
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 27 Rules
  • 7 Models

Vendor: Unix

ProductEvent TypesMITRE TTPContent
Auditbeat
  • app-activity
  • app-login
  • process-created-failed
  • process-network
  • remote-logon
  • web-activity-denied
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1220 - XSL Script Processing
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 53 Rules
  • 18 Models
Unix
  • account-creation
  • account-deleted
  • account-password-reset
  • authentication-failed
  • authentication-successful
  • batch-logon
  • config-change
  • database-access
  • database-query
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-app-login
  • failed-logon
  • file-permission-change
  • file-read
  • kerberos-logon
  • local-logon
  • member-added
  • member-removed
  • netflow-connection
  • network-alert
  • process-created
  • process-created-failed
  • remote-logon
  • security-alert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 246 Rules
  • 36 Models
Unix Auditd
  • account-creation
  • account-deleted
  • app-activity
  • authentication-failed
  • authentication-successful
  • config-change
  • database-login
  • dlp-alert
  • failed-logon
  • local-logon
  • member-added
  • member-removed
  • process-created
  • process-created-failed
  • remote-logon
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 242 Rules
  • 33 Models
Unix Privilege Management
  • dlp-alert
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: VMS Software

ProductEvent TypesMITRE TTPContent
OpenVMS
  • app-activity-failed
  • batch-logon
  • failed-logon
  • file-delete
  • file-read
T1027 - Obfuscated Files or Information
T1204 - User Execution
T1210 - Exploitation of Remote Services
  • 5 Rules
  • 3 Models

Vendor: VMware

ProductEvent TypesMITRE TTPContent
App Control
  • app-activity
  • batch-logon
  • dlp-email-alert-out-failed
  • failed-physical-access
  • file-alert
  • file-delete
  • file-write
  • local-logon
  • process-alert
  • process-created
  • security-alert
  • usb-write
  • workstation-locked
  • workstation-unlocked
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 248 Rules
  • 39 Models
Carbon Black Cloud Endpoint Standard
  • config-change
  • file-write
  • network-connection-failed
  • network-connection-successful
  • process-created
  • process-created-failed
  • security-alert
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 248 Rules
  • 37 Models
Endpoint Detection and Response
  • config-change
  • file-read
  • file-write
  • process-created
  • web-activity-denied
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1189 - Drive-by Compromise
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 270 Rules
  • 41 Models
NSX FW
  • network-connection-successful
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 29 Rules
  • 8 Models
VMWare ID Manager (VIDM)
  • app-activity
  • app-login
  • remote-logon
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models
VMware ESXi
  • computer-logon
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models
VMware Horizon
  • authentication-failed
  • authentication-successful
T1078 - Valid Accounts
  • 1 Rules
VMware NSX
  • app-activity-failed
  • network-connection-successful
T1071 - Application Layer Protocol
  • 1 Rules
VMware VCenter
  • account-password-change
  • app-activity-failed
  • ds-access
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
T1207 - Rogue Domain Controller
  • 4 Rules
  • 2 Models
VMware View
  • account-password-change
  • app-login
  • authentication-failed
  • failed-app-login
  • remote-logon
T1078 - Valid Accounts
T1204 - User Execution
  • 3 Rules
  • 2 Models

Vendor: Varonis

ProductEvent TypesMITRE TTPContent
Data Security Platform
  • file-delete
  • file-permission-change
  • file-read
  • file-write
  • network-alert
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 4 Models

Vendor: Vectra

ProductEvent TypesMITRE TTPContent
Vectra Cognito Detect
  • network-connection-failed
  • security-alert
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1204 - User Execution
  • 6 Rules
  • 4 Models

Vendor: Vormetric

ProductEvent TypesMITRE TTPContent
Vormetric
  • account-switch
  • file-read
T1027 - Obfuscated Files or Information
T1204 - User Execution
  • 3 Rules
  • 3 Models

Vendor: Watchguard

ProductEvent TypesMITRE TTPContent
Watchguard
  • app-activity-failed
  • network-alert
  • network-connection-successful
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 31 Rules
  • 10 Models

Vendor: Weblogin

ProductEvent TypesMITRE TTPContent
Weblogin
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 4 Rules
  • 4 Models

Vendor: Workday

ProductEvent TypesMITRE TTPContent
Workday
  • account-password-change
  • app-login
  • failed-app-login
  • file-write
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1078 - Valid Accounts
T1204 - User Execution
T1218.011 - Signed Binary Proxy Execution: Rundll32
  • 7 Rules
  • 3 Models

Vendor: XPS

ProductEvent TypesMITRE TTPContent
XPS
  • app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Xceedium

ProductEvent TypesMITRE TTPContent
Xceedium
  • app-activity
  • app-login
T1078 - Valid Accounts
  • 1 Rules

Vendor: Xerox

ProductEvent TypesMITRE TTPContent
Xerox
  • app-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: Zeek

ProductEvent TypesMITRE TTPContent
Zeek Network Security Monitor
  • app-activity
  • app-login
  • authentication-failed
  • authentication-successful
  • computer-logon
  • dlp-alert
  • dlp-email-alert-in
  • dns-query
  • dns-response
  • failed-logon
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • nac-failed-logon
  • nac-logon
  • network-alert
  • network-connection-successful
  • ntlm-logon
  • remote-logon
  • share-access
  • web-activity-allowed
  • web-activity-denied
T1003.002 - T1003.002
T1027 - Obfuscated Files or Information
T1055.012 - T1055.012
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1071.004 - Application Layer Protocol: DNS
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1210 - Exploitation of Remote Services
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 44 Rules
  • 12 Models

Vendor: Zlock

ProductEvent TypesMITRE TTPContent
Zlock
  • app-activity
T1078 - Valid Accounts
  • 1 Rules

Vendor: Zscaler

ProductEvent TypesMITRE TTPContent
Zscaler Internet Access
  • database-update
  • dlp-alert
  • image-loaded
  • network-connection-failed
  • network-connection-successful
  • web-activity-allowed
  • web-activity-denied
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204 - User Execution
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 36 Rules
  • 10 Models
Zscaler Private Access
  • process-created
  • vpn-login
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1012 - Query Registry
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.004 - Obfuscated Files or Information: Compile After Delivery
T1036 - Masquerading
T1036.005 - Masquerading: Match Legitimate Name or Location
T1046 - Network Service Scanning
T1047 - Windows Management Instrumentation
T1053 - Scheduled Task/Job
T1053.005 - Scheduled Task/Job: Scheduled Task
T1055 - Process Injection
T1055.012 - T1055.012
T1059 - Command and Scripting Interperter
T1059.001 - Command and Scripting Interperter: PowerShell
T1059.002 - T1059.002
T1059.003 - T1059.003
T1059.004 - T1059.004
T1059.005 - T1059.005
T1059.006 - T1059.006
T1064 - Scripting
T1070.005 - T1070.005
T1078 - Valid Accounts
T1105 - Ingress Tool Transfer
T1112 - Modify Registry
T1123 - Audio Capture
T1127 - Trusted Developer Utilities Proxy Execution
T1127.001 - Trusted Developer Utilities Proxy Execution: MSBuild
T1134.001 - Access Token Manipulation: Token Impersonation/Theft
T1140 - Deobfuscate/Decode Files or Information
T1175 - T1175
T1197 - BITS Jobs
T1202 - Indirect Command Execution
T1203 - Exploitation for Client Execution
T1204 - User Execution
T1210 - Exploitation of Remote Services
T1218 - Signed Binary Proxy Execution
T1218.001 - Signed Binary Proxy Execution: Compiled HTML File
T1218.002 - Signed Binary Proxy Execution: Control Panel
T1218.004 - Signed Binary Proxy Execution: InstallUtil
T1218.005 - T1218.005
T1218.007 - Signed Binary Proxy Execution: Msiexec
T1218.010 - Signed Binary Proxy Execution: Regsvr32
T1218.011 - Signed Binary Proxy Execution: Rundll32
T1220 - XSL Script Processing
T1490 - Inhibit System Recovery
T1505.003 - Server Software Component: Web Shell
T1543.003 - Create or Modify System Process: Windows Service
T1546.001 - T1546.001
T1547.001 - T1547.001
T1557.001 - T1557.001
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
T1566.001 - T1566.001
T1569 - System Services
T1574 - Hijack Execution Flow
T1574.002 - Hijack Execution Flow: DLL Side-Loading
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 240 Rules
  • 33 Models

Vendor: eDocs

ProductEvent TypesMITRE TTPContent
eDocs
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 27 Rules
  • 7 Models

Vendor: iBoss

ProductEvent TypesMITRE TTPContent
Secure Web Gateway
  • account-deleted
  • web-activity-allowed
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 8 Models

Vendor: iManage

ProductEvent TypesMITRE TTPContent
iManage
  • app-activity
  • authentication-failed
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 28 Rules
  • 7 Models

Vendor: jSONAR

ProductEvent TypesMITRE TTPContent
SonarG
  • local-logon
T1204 - User Execution
  • 2 Rules
  • 2 Models

Vendor: oVirt

ProductEvent TypesMITRE TTPContent
oVirt
  • app-activity
  • app-login
  • failed-app-login
  • security-alert
T1078 - Valid Accounts
T1204 - User Execution
  • 5 Rules
  • 4 Models

Vendor: pfSense

ProductEvent TypesMITRE TTPContent
pfSense
  • file-read
T1027 - Obfuscated Files or Information
  • 1 Rules
  • 1 Models

Vendor: xsuite

ProductEvent TypesMITRE TTPContent
xsuite
  • web-activity-denied
T1071 - Application Layer Protocol
T1071.001 - Application Layer Protocol: Web Protocols
T1090.003 - Proxy: Multi-hop Proxy
T1189 - Drive-by Compromise
T1204.001 - T1204.001
T1566.002 - Phishing: Spearphishing Link
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
  • 27 Rules
  • 7 Models