| Abnormal Authentication & Access | app-activity ↳dell-sw-mix-app-activity-assignedipaddress ↳dell-sw-kv-app-activity-appactivity
authentication-successful ↳dell-sw-kv-alert-trigger-success-security
failed-vpn-login ↳dell-sw-kv-vpn-login-fail-sslvpn ↳dell-sw-kv-vpn-login-fail-140
vpn-login ↳sonicwall-sw-kv-vpn-login-success-1080 ↳dell-sw-kv-alert-trigger-success-security ↳dell-sw-kv-vpn-login-success-netextenderconnected ↳dell-sw-kv-vpn-login-success-userloginsuccessful
vpn-logout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn
web-activity-allowed ↳dell-sw-kv-http-session-category
web-activity-denied ↳dell-sw-kv-http-session-category
| T1021 - Remote Services T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1078 - Valid Accounts T1133 - External Remote Services
| |
| Account Manipulation | app-activity ↳dell-sw-mix-app-activity-assignedipaddress ↳dell-sw-kv-app-activity-appactivity
vpn-logout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1484 - Group Policy Modification
| |
| Brute Force Attack | vpn-logout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn
| T1110 - Brute Force
| |
| Cryptomining | web-activity-allowed ↳dell-sw-kv-http-session-category
web-activity-denied ↳dell-sw-kv-http-session-category
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1496 - Resource Hijacking
| |
| Data Access | app-activity ↳dell-sw-mix-app-activity-assignedipaddress ↳dell-sw-kv-app-activity-appactivity
vpn-logout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn
| T1078 - Valid Accounts T1110 - Brute Force
| |
| Data Exfiltration | vpn-logout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn
web-activity-allowed ↳dell-sw-kv-http-session-category
web-activity-denied ↳dell-sw-kv-http-session-category
| T1041 - Exfiltration Over C2 Channel T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols T1133 - External Remote Services T1567 - Exfiltration Over Web Service T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage T1568 - Dynamic Resolution T1568.002 - Dynamic Resolution: Domain Generation Algorithms TA0010 - TA0010
| |
| Phishing | vpn-logout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn
web-activity-allowed ↳dell-sw-kv-http-session-category
web-activity-denied ↳dell-sw-kv-http-session-category
| T1189 - Drive-by Compromise T1204 - User Execution T1204.001 - T1204.001 T1534 - Internal Spearphishing T1566 - Phishing T1566.002 - Phishing: Spearphishing Link T1598 - T1598 T1598.003 - T1598.003
| |
| Physical Security | vpn-login ↳sonicwall-sw-kv-vpn-login-success-1080 ↳dell-sw-kv-alert-trigger-success-security ↳dell-sw-kv-vpn-login-success-netextenderconnected ↳dell-sw-kv-vpn-login-success-userloginsuccessful
| T1133 - External Remote Services
| |
| Privilege Escalation | app-activity ↳dell-sw-mix-app-activity-assignedipaddress ↳dell-sw-kv-app-activity-appactivity
vpn-logout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1555 - Credentials from Password Stores T1555.005 - T1555.005
| |
| Workforce Protection | web-activity-allowed ↳dell-sw-kv-http-session-category
| T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols
| |
| Next Page -->> | | | |