Vendor: Jumpcloud

April 15, 2026 · View on GitHub

Product: Jumpcloud

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
1114715141
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-creation
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events

account-deleted
jumpcloud-jc-json-directoryinsights-events

account-disabled
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events

account-enabled
jumpcloud-jc-json-directoryinsights-events

account-lockout
jumpcloud-jc-json-directoryinsights-events

account-password-change
jumpcloud-jc-json-directoryinsights-events

account-password-reset
jumpcloud-jc-json-directoryinsights-events

account-unlocked
jumpcloud-jc-json-directoryinsights-events

app-activity
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events

app-login
jumpcloud-jc-str-app-login-success
jumpcloud-jc-json-directoryinsights-events

failed-app-login
jumpcloud-jc-str-app-login-fail
jumpcloud-jc-json-directoryinsights-events

privileged-access
jumpcloud-jc-json-directoryinsights-events
T1078 - Valid Accounts
T1110 - Brute Force
T1133 - External Remote Services
  • 16 Rules
  • 4 Models
Account Manipulationaccount-creation
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events

account-deleted
jumpcloud-jc-json-directoryinsights-events

account-password-change
jumpcloud-jc-json-directoryinsights-events

account-password-reset
jumpcloud-jc-json-directoryinsights-events

app-activity
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
jumpcloud-jc-json-directoryinsights-events
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
T1531 - Account Access Removal
  • 25 Rules
  • 9 Models
Brute Force Attackaccount-lockout
jumpcloud-jc-json-directoryinsights-events
T1110 - Brute Force
  • 1 Rules
Lateral Movementapp-login
jumpcloud-jc-str-app-login-success
jumpcloud-jc-json-directoryinsights-events

failed-app-login
jumpcloud-jc-str-app-login-fail
jumpcloud-jc-json-directoryinsights-events
T1078 - Valid Accounts
T1090 - Proxy
T1090.003 - Proxy: Multi-hop Proxy
  • 2 Rules
Malwareapp-login
jumpcloud-jc-str-app-login-success
jumpcloud-jc-json-directoryinsights-events

privileged-access
jumpcloud-jc-json-directoryinsights-events
T1078 - Valid Accounts
TA0002 - TA0002
  • 5 Rules
  • 2 Models
Ransomwareapp-login
jumpcloud-jc-str-app-login-success
jumpcloud-jc-json-directoryinsights-events

failed-app-login
jumpcloud-jc-str-app-login-fail
jumpcloud-jc-json-directoryinsights-events
T1078 - Valid Accounts
  • 2 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

Create Account

External Remote Services

Valid Accounts

Account Manipulation

Create Account: Create: Local Account

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Valid Accounts

Brute Force

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy

Account Access Removal