Rules by Product and UseCase

April 15, 2026 · View on GitHub

Vendor: Apache

Product: Apache

Use-Case: Ransomware

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
10221
Event TypeRulesModels
web-activity-allowedT1071 - Application Layer Protocol
WEB-UI-Ransomware: User attempted to connect to IP address which is associated to Ransomware

T1071.001 - Application Layer Protocol: Web Protocols
WEB-UI-Ransomware: User attempted to connect to IP address which is associated to Ransomware
web-activity-deniedT1071 - Application Layer Protocol
WEB-UI-Ransomware: User attempted to connect to IP address which is associated to Ransomware

T1071.001 - Application Layer Protocol: Web Protocols
WEB-UI-Ransomware: User attempted to connect to IP address which is associated to Ransomware