| Abnormal Authentication & Access | app-activity ↳cimcor-cimtrak-json-app-activity-success-catchall
app-login ↳cimcor-cimtrak-json-app-activity-success-catchall
member-added ↳cimcor-cimtrak-json-app-activity-success-catchall
member-removed ↳cimcor-cimtrak-json-app-activity-success-catchall
| T1078 - Valid Accounts T1133 - External Remote Services
| |
| Account Manipulation | app-activity ↳cimcor-cimtrak-json-app-activity-success-catchall
member-added ↳cimcor-cimtrak-json-app-activity-success-catchall
member-removed ↳cimcor-cimtrak-json-app-activity-success-catchall
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account
| |
| Data Exfiltration | file-write ↳cimcor-cimtrak-json-app-activity-success-catchall ↳cimcor-cimtrak-json-app-activity-success-catchall
| TA0002 - TA0002
| |
| Data Leak | app-activity ↳cimcor-cimtrak-json-app-activity-success-catchall
file-write ↳cimcor-cimtrak-json-app-activity-success-catchall ↳cimcor-cimtrak-json-app-activity-success-catchall
| T1114 - Email Collection T1114.001 - T1114.001 T1114.003 - Email Collection: Email Forwarding Rule
| |
| Destruction of Data | file-delete ↳cimcor-cimtrak-json-app-activity-success-catchall
| T1070 - Indicator Removal on Host T1070.004 - Indicator Removal on Host: File Deletion T1485 - Data Destruction
| |
| Lateral Movement | app-login ↳cimcor-cimtrak-json-app-activity-success-catchall
| T1090 - Proxy T1090.003 - Proxy: Multi-hop Proxy
| |
| Malware | app-login ↳cimcor-cimtrak-json-app-activity-success-catchall
file-write ↳cimcor-cimtrak-json-app-activity-success-catchall ↳cimcor-cimtrak-json-app-activity-success-catchall
| T1003 - OS Credential Dumping T1003.002 - T1003.002 T1078 - Valid Accounts T1505 - Server Software Component T1505.003 - Server Software Component: Web Shell T1547 - Boot or Logon Autostart Execution T1547.001 - T1547.001 TA0002 - TA0002
| |
| Privilege Escalation | app-activity ↳cimcor-cimtrak-json-app-activity-success-catchall
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
| |
| Ransomware | app-login ↳cimcor-cimtrak-json-app-activity-success-catchall
file-write ↳cimcor-cimtrak-json-app-activity-success-catchall ↳cimcor-cimtrak-json-app-activity-success-catchall
| T1078 - Valid Accounts T1486 - Data Encrypted for Impact
| |
| Next Page -->> | | | |