Vendor: Commvault

April 15, 2026 · View on GitHub

Product: Commvault ThreatWise

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
69281221
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Compromised Credentialssecurity-alert
commvault-threatwise-str-alert-trigger-success-reconnaissance
commvault-threatwise-str-alert-trigger-success-synscan
T1027 - Obfuscated Files or Information
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1078 - Valid Accounts
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
  • 23 Rules
  • 9 Models
Lateral Movementnetwork-connection-successful
commvault-threatwise-str-traps-catchall

security-alert
commvault-threatwise-str-alert-trigger-success-reconnaissance
commvault-threatwise-str-alert-trigger-success-synscan
T1027 - Obfuscated Files or Information
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1071 - Application Layer Protocol
T1090 - Proxy
T1090.003 - Proxy: Multi-hop Proxy
T1190 - Exploit Public Fasing Application
TA0010 - TA0010
TA0011 - TA0011
  • 41 Rules
  • 17 Models
Malwarenetwork-connection-successful
commvault-threatwise-str-traps-catchall

security-alert
commvault-threatwise-str-alert-trigger-success-reconnaissance
commvault-threatwise-str-alert-trigger-success-synscan
TA0002 - TA0002
TA0011 - TA0011
  • 7 Rules
  • 2 Models
Privileged Activitysecurity-alert
commvault-threatwise-str-alert-trigger-success-reconnaissance
commvault-threatwise-str-alert-trigger-success-synscan
T1068 - Exploitation for Privilege Escalation
  • 1 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Valid Accounts

Exploitation for Privilege Escalation

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Obfuscated Files or Information

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy