| Abnormal Authentication & Access | account-lockout ↳accellion-kw-kv-user-lock-success-useraccountlocked
account-password-change ↳accellion-kiteworks-kv-user-password-modify-success-updatedpassword ↳accellion-kw-kv-user-password-modify-success-resetpassword
account-unlocked ↳accellion-kw-kv-user-unlock-success-useraccountunlocked ↳accellion-kw-kv-user-unlock-success-reactivateuser
app-activity ↳accellion-kw-kv-file-upload-success-uploadedfile1 ↳accellion-kw-kv-app-activity-success-createddraft ↳accellion-kw-kv-app-activity-success-requestedafile ↳accellion-kw-kv-app-activity-success-viewedemailsubject ↳accellion-kw-kv-app-activity-success-userprofile ↳accellion-kw-kv-app-activity-success-draftchanged ↳accellion-kw-kv-app-activity-success-userdeleted
app-login ↳accellion-kw-str-app-login-success-sessionstarted ↳accellion-kw-mix-app-login-success-loggedin
failed-app-login ↳accellion-kw-kv-app-login-fail-userlogin
member-added ↳accellion-kw-kv-group-member-add-adduser
| T1078 - Valid Accounts T1110 - Brute Force T1133 - External Remote Services
| |
| Account Manipulation | account-password-change ↳accellion-kiteworks-kv-user-password-modify-success-updatedpassword ↳accellion-kw-kv-user-password-modify-success-resetpassword
app-activity ↳accellion-kw-kv-file-upload-success-uploadedfile1 ↳accellion-kw-kv-app-activity-success-createddraft ↳accellion-kw-kv-app-activity-success-requestedafile ↳accellion-kw-kv-app-activity-success-viewedemailsubject ↳accellion-kw-kv-app-activity-success-userprofile ↳accellion-kw-kv-app-activity-success-draftchanged ↳accellion-kw-kv-app-activity-success-userdeleted
member-added ↳accellion-kw-kv-group-member-add-adduser
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account
| |
| Brute Force Attack | account-lockout ↳accellion-kw-kv-user-lock-success-useraccountlocked
| T1110 - Brute Force
| |
| Data Exfiltration | file-write ↳accellion-kw-kv-file-write-success-createdfolder
| TA0002 - TA0002
| |
| Destruction of Data | file-delete ↳accellion-kw-kv-file-delete-success-deletedfolder
| T1070 - Indicator Removal on Host T1070.004 - Indicator Removal on Host: File Deletion T1485 - Data Destruction
| |
| Lateral Movement | app-login ↳accellion-kw-str-app-login-success-sessionstarted ↳accellion-kw-mix-app-login-success-loggedin
failed-app-login ↳accellion-kw-kv-app-login-fail-userlogin
| T1078 - Valid Accounts T1090 - Proxy T1090.003 - Proxy: Multi-hop Proxy
| |
| Malware | app-login ↳accellion-kw-str-app-login-success-sessionstarted ↳accellion-kw-mix-app-login-success-loggedin
dlp-email-alert-out ↳accellion-kw-kv-email-send-success-withfiles
file-write ↳accellion-kw-kv-file-write-success-createdfolder
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1078 - Valid Accounts T1190 - Exploit Public Fasing Application T1505 - Server Software Component T1505.003 - Server Software Component: Web Shell T1547 - Boot or Logon Autostart Execution T1547.001 - T1547.001 TA0002 - TA0002
| |
| Phishing | dlp-email-alert-out ↳accellion-kw-kv-email-send-success-withfiles
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
| |
| Ransomware | app-login ↳accellion-kw-str-app-login-success-sessionstarted ↳accellion-kw-mix-app-login-success-loggedin
failed-app-login ↳accellion-kw-kv-app-login-fail-userlogin
file-write ↳accellion-kw-kv-file-write-success-createdfolder
| T1078 - Valid Accounts T1486 - Data Encrypted for Impact
| |
| Workforce Protection | dlp-email-alert-out ↳accellion-kw-kv-email-send-success-withfiles
| T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
| |
| Next Page -->> | | | |