Vendor: APC

April 15, 2026 · View on GitHub

Product: APC

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
104422050
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessauthentication-failed
apc-a-kv-endpoint-login-fail-smtpauthfail

failed-app-login
apc-a-str-app-login-fail-invalidcredentials

remote-logon
apc-a-str-endpoint-login-success-webuser
T1021 - Remote Services
T1078 - Valid Accounts
T1078.002 - T1078.002
T1078.003 - Valid Accounts: Local Accounts
T1133 - External Remote Services
  • 32 Rules
  • 14 Models
Compromised Credentialsfailed-app-login
apc-a-str-app-login-fail-invalidcredentials

network-alert
apc-a-str-alert-trigger-success-0004

remote-logon
apc-a-str-endpoint-login-success-webuser
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1078 - Valid Accounts
T1078.002 - T1078.002
T1078.003 - Valid Accounts: Local Accounts
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
T1550 - Use Alternate Authentication Material
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
  • 58 Rules
  • 25 Models
Data Accessfailed-app-login
apc-a-str-app-login-fail-invalidcredentials
T1078 - Valid Accounts
  • 1 Rules
Lateral Movementauthentication-failed
apc-a-kv-endpoint-login-fail-smtpauthfail

failed-app-login
apc-a-str-app-login-fail-invalidcredentials

remote-logon
apc-a-str-endpoint-login-success-webuser
T1018 - Remote System Discovery
T1021 - Remote Services
T1078 - Valid Accounts
T1090 - Proxy
T1090.003 - Proxy: Multi-hop Proxy
T1550 - Use Alternate Authentication Material
T1550.002 - Use Alternate Authentication Material: Pass the Hash
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
  • 28 Rules
  • 12 Models
Malwarenetwork-alert
apc-a-str-alert-trigger-success-0004

remote-logon
apc-a-str-endpoint-login-success-webuser
T1078 - Valid Accounts
T1550 - Use Alternate Authentication Material
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
TA0002 - TA0002
  • 6 Rules
  • 2 Models
Privilege Abusedlp-email-alert-in-failed
apc-a-kv-email-receive-fail-reject

failed-app-login
apc-a-str-app-login-fail-invalidcredentials

remote-logon
apc-a-str-endpoint-login-success-webuser
T1078 - Valid Accounts
T1078.002 - T1078.002
  • 10 Rules
  • 6 Models
Privilege Escalationremote-logon
apc-a-str-endpoint-login-success-webuser
T1078 - Valid Accounts
T1555 - Credentials from Password Stores
T1555.005 - T1555.005
  • 2 Rules
  • 1 Models
Privileged Activitydlp-email-alert-in-failed
apc-a-kv-email-receive-fail-reject

failed-app-login
apc-a-str-app-login-fail-invalidcredentials

remote-logon
apc-a-str-endpoint-login-success-webuser
T1021 - Remote Services
T1068 - Exploitation for Privilege Escalation
T1078 - Valid Accounts
T1078.002 - T1078.002
  • 16 Rules
  • 7 Models
Ransomwareauthentication-failed
apc-a-kv-endpoint-login-fail-smtpauthfail

failed-app-login
apc-a-str-app-login-fail-invalidcredentials

remote-logon
apc-a-str-endpoint-login-success-webuser
T1078 - Valid Accounts
  • 1 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Valid Accounts

Exploitation for Privilege Escalation

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Use Alternate Authentication Material

Use Alternate Authentication Material: Pass the Hash

Use Alternate Authentication Material: Pass the Ticket

Obfuscated Files or Information

Valid Accounts: Local Accounts

Steal or Forge Kerberos Tickets

Credentials from Password Stores

Steal or Forge Kerberos Tickets: Kerberoasting

Remote System Discovery

Remote Services

Use Alternate Authentication Material

Proxy: Multi-hop Proxy

Proxy