Vendor: Cisco

April 15, 2026 · View on GitHub

Product: Cisco Email Security

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
39174435
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Data Leakdlp-email-alert-out
cisco-se-cef-email-send-receive-success-suser
cisco-se-cef-email-send-receive-esafriendlyfrom
cisco-se-cef-email-send-receive-consolidatedlogevent
cisco-ie-kv-email-send-receive-summary
cisco-ie-str-email-to
cisco-ie-cef-email-to
cisco-ie-cef-email-from
cisco-ie-mix-email-send-receive-from
cisco-ie-cef-email-bytesfrom
cisco-ie-str-email-bytesfrom
cisco-ie-cef-email-subject
cisco-ie-str-email-subject
cisco-ie-str-email-attachment
cisco-ie-str-email-spam
cisco-ie-cef-email-spam
cisco-ie-str-email-antivirus
cisco-ie-cef-email-antivirus
cisco-ie-str-email-av-verdict
cisco-ie-cef-email-graymail
cisco-ie-str-email-graymail
cisco-ie-str-email-url
cisco-ie-str-email-url-1
cisco-ie-str-email-file-verdict
cisco-ie-cef-email-response
cisco-ie-cef-email-finished
cisco-ie-str-email-finished
cisco-ie-kv-email-alert
cisco-ie-kv-email-attachment
cisco-ie-kv-email-response
cisco-ie-csv-email-outcome
cisco-secureemail-cef-email-send-success-logevent
cisco-secureemail-json-email-send-receive-esa
cisco-secureemail-cef-email-receive-fail-secureemailgateway
cisco-ie-str-email-success-dcid

dlp-email-alert-out-failed
cisco-se-cef-email-send-receive-consolidatedlogevent
cisco-ie-kv-email-send-receive-summary
cisco-ie-str-email-to
cisco-ie-cef-email-to
cisco-ie-cef-email-from
cisco-ie-mix-email-send-receive-from
cisco-ie-cef-email-bytesfrom
cisco-ie-str-email-bytesfrom
cisco-ie-cef-email-subject
cisco-ie-str-email-subject
cisco-ie-str-email-attachment
cisco-ie-str-email-spam
cisco-ie-cef-email-spam
cisco-ie-str-email-antivirus
cisco-ie-cef-email-antivirus
cisco-ie-str-email-av-verdict
cisco-ie-str-email-url
cisco-ie-str-email-url-1
cisco-ie-str-email-file-verdict
cisco-ie-cef-email-graymail
cisco-ie-str-email-graymail
cisco-ie-str-email-aborted
cisco-ie-cef-email-finished
cisco-ie-str-email-finished
cisco-ie-kv-email-alert
cisco-ie-kv-email-attachment
cisco-ie-kv-email-response
cisco-ie-csv-email-outcome
cisco-secureemail-cef-email-send-success-logevent
cisco-secureemail-json-email-send-receive-esa
cisco-secureemail-cef-email-receive-fail-secureemailgateway
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 34 Rules
  • 16 Models
Malwaredlp-email-alert-in
cisco-secureemail-cef-email-send-success-logevent
cisco-secureemail-cef-email-receive-fail-secureemailgateway
cisco-se-cef-email-send-receive-success-suser
cisco-secureemail-json-email-send-receive-esa
cisco-se-cef-email-send-receive-esafriendlyfrom
cisco-se-cef-email-send-receive-consolidatedlogevent
cisco-ie-kv-email-send-receive-summary
cisco-ie-str-email-to
cisco-ie-cef-email-to
cisco-ie-cef-email-from
cisco-ie-mix-email-send-receive-from
cisco-ie-cef-email-bytesfrom
cisco-ie-str-email-bytesfrom
cisco-ie-cef-email-subject
cisco-ie-str-email-subject
cisco-ie-str-email-attachment
cisco-ie-str-email-spam
cisco-ie-cef-email-spam
cisco-ie-str-email-antivirus
cisco-ie-cef-email-antivirus
cisco-ie-str-email-av-verdict
cisco-ie-str-email-url
cisco-ie-str-email-url-1
cisco-ie-str-email-file-verdict
cisco-ie-cef-email-graymail
cisco-ie-str-email-graymail
cisco-ie-cef-email-response
cisco-ie-cef-email-finished
cisco-ie-str-email-finished
cisco-ie-kv-email-alert
cisco-ie-kv-email-attachment
cisco-ie-kv-email-response
cisco-ie-csv-email-outcome
cisco-ie-str-email-success-dcid

dlp-email-alert-out
cisco-se-cef-email-send-receive-success-suser
cisco-se-cef-email-send-receive-esafriendlyfrom
cisco-se-cef-email-send-receive-consolidatedlogevent
cisco-ie-kv-email-send-receive-summary
cisco-ie-str-email-to
cisco-ie-cef-email-to
cisco-ie-cef-email-from
cisco-ie-mix-email-send-receive-from
cisco-ie-cef-email-bytesfrom
cisco-ie-str-email-bytesfrom
cisco-ie-cef-email-subject
cisco-ie-str-email-subject
cisco-ie-str-email-attachment
cisco-ie-str-email-spam
cisco-ie-cef-email-spam
cisco-ie-str-email-antivirus
cisco-ie-cef-email-antivirus
cisco-ie-str-email-av-verdict
cisco-ie-cef-email-graymail
cisco-ie-str-email-graymail
cisco-ie-str-email-url
cisco-ie-str-email-url-1
cisco-ie-str-email-file-verdict
cisco-ie-cef-email-response
cisco-ie-cef-email-finished
cisco-ie-str-email-finished
cisco-ie-kv-email-alert
cisco-ie-kv-email-attachment
cisco-ie-kv-email-response
cisco-ie-csv-email-outcome
cisco-secureemail-cef-email-send-success-logevent
cisco-secureemail-json-email-send-receive-esa
cisco-secureemail-cef-email-receive-fail-secureemailgateway
cisco-ie-str-email-success-dcid
T1190 - Exploit Public Fasing Application
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Valid Accounts

Exploit Public Fasing Application

Valid Accounts

Valid Accounts

Valid Accounts

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol