| Abnormal Authentication & Access | web-activity-allowed ↳cisco-securewebapp-str-http-session-accesslog ↳cisco-securewebapp-str-http-session-squid ↳cisco-iws-csv-http-session-tcpmissssl ↳cisco-iws-csv-http-session-tcprefreshhit ↳cisco-iws-csv-http-session-tcpmiss
web-activity-denied ↳cisco-securewebapp-str-http-session-accesslog ↳cisco-securewebapp-str-http-session-squid ↳cisco-iws-csv-http-session-tcpmissssl ↳cisco-iws-csv-http-session-tcprefreshhit ↳cisco-iws-csv-http-session-tcpmiss
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols
| |
| Compromised Credentials | web-activity-allowed ↳cisco-securewebapp-str-http-session-accesslog ↳cisco-securewebapp-str-http-session-squid ↳cisco-iws-csv-http-session-tcpmissssl ↳cisco-iws-csv-http-session-tcprefreshhit ↳cisco-iws-csv-http-session-tcpmiss
web-activity-denied ↳cisco-securewebapp-str-http-session-accesslog ↳cisco-securewebapp-str-http-session-squid ↳cisco-iws-csv-http-session-tcpmissssl ↳cisco-iws-csv-http-session-tcprefreshhit ↳cisco-iws-csv-http-session-tcpmiss
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1102 - Web Service T1189 - Drive-by Compromise T1190 - Exploit Public Fasing Application T1204 - User Execution T1204.001 - T1204.001 T1566 - Phishing T1566.002 - Phishing: Spearphishing Link T1568 - Dynamic Resolution T1568.002 - Dynamic Resolution: Domain Generation Algorithms
| |
| Workforce Protection | web-activity-allowed ↳cisco-securewebapp-str-http-session-accesslog ↳cisco-securewebapp-str-http-session-squid ↳cisco-iws-csv-http-session-tcpmissssl ↳cisco-iws-csv-http-session-tcprefreshhit ↳cisco-iws-csv-http-session-tcpmiss
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols
| |
| Next Page -->> | | | |