Vendor: BeyondTrust

April 15, 2026 · View on GitHub

Product: BeyondInsight

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
874010620
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-password-reset
beyondtrust-bi-leef-user-password-reset-success

app-activity
beyondtrust-bi-cef-app-activity-success-approve
beyondtrust-bi-cef-app-activity-success-appauditdelete
beyondtrust-bi-cef-app-activity-success-appauditadd
beyondtrust-bi-leef-app-activity-success-system
beyondtrust-bi-leef-app-activity-success-managed
beyondtrust-bi-leef-app-activity-success-managedaccount
beyondtrust-bi-leef-app-activity-success-releasepasswordreset
beyondtrust-bi-leef-app-activity-success-turnedoff
beyondtrust-bi-leef-app-activity-success-passwordreset
beyondtrust-bi-leef-app-activity-success-passwordchange
beyondtrust-bi-leef-app-activity-success-updated
beyondtrust-bi-cef-user-create-success-add
beyondtrust-bi-leef-app-activity-success-change
beyondtrust-bi-json-app-activity-pbps
beyondtrust-bi-json-app-activity-appaudit
beyondtrust-bi-leef-app-activity-success-fail-bi

app-login
beyondtrust-bi-leef-app-login-success-login
beyondtrust-bi-leef-app-login-success-pmmlogin
beyondtrust-bi-cef-app-login-success-login
beyondtrust-bi-json-app-login-pbps

failed-app-login
beyondtrust-bi-cef-app-login-fail-loginfailure
beyondtrust-bi-leef-app-login-fail-loginfailure
beyondtrust-bi-leef-app-login-fail-connectfailure
beyondtrust-bi-json-app-login-pbps

privileged-access
beyondtrust-powerbroker-kv-user-privilege-use-success-elevation
T1078 - Valid Accounts
T1133 - External Remote Services
  • 15 Rules
  • 4 Models
Account Manipulationaccount-password-reset
beyondtrust-bi-leef-user-password-reset-success

app-activity
beyondtrust-bi-cef-app-activity-success-approve
beyondtrust-bi-cef-app-activity-success-appauditdelete
beyondtrust-bi-cef-app-activity-success-appauditadd
beyondtrust-bi-leef-app-activity-success-system
beyondtrust-bi-leef-app-activity-success-managed
beyondtrust-bi-leef-app-activity-success-managedaccount
beyondtrust-bi-leef-app-activity-success-releasepasswordreset
beyondtrust-bi-leef-app-activity-success-turnedoff
beyondtrust-bi-leef-app-activity-success-passwordreset
beyondtrust-bi-leef-app-activity-success-passwordchange
beyondtrust-bi-leef-app-activity-success-updated
beyondtrust-bi-cef-user-create-success-add
beyondtrust-bi-leef-app-activity-success-change
beyondtrust-bi-json-app-activity-pbps
beyondtrust-bi-json-app-activity-appaudit
beyondtrust-bi-leef-app-activity-success-fail-bi
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 4 Rules
  • 1 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Account Manipulation

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Valid Accounts

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy