Rules by Product and UseCase

April 15, 2026 · View on GitHub

Vendor: APC

Product: APC

Use-Case: Privilege Escalation

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
21310
Event TypeRulesModels
remote-logonT1078 - Valid Accounts
AS-PV-UHWoPC: Access to Password Vault managed asset with no password checkout for user
DC18-new: Account switch by new user

T1555 - Credentials from Password Stores
AS-PV-UHWoPC: Access to Password Vault managed asset with no password checkout for user

T1555.005 - T1555.005
AS-PV-UHWoPC: Access to Password Vault managed asset with no password checkout for user
AS-PV-OA: Password retrieval based accounts