| Abnormal Authentication & Access | app-activity ↳kemp-loadbalancer-kv-app-activity-success-rule ↳kemp-loadmaster-str-app-activity-l4d
authentication-failed ↳kemp-loadmaster-str-app-authentication-fail-loginfailed
| T1078 - Valid Accounts T1133 - External Remote Services
| |
| Account Manipulation | app-activity ↳kemp-loadbalancer-kv-app-activity-success-rule ↳kemp-loadmaster-str-app-activity-l4d
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
| |
| Compromised Credentials | app-activity ↳kemp-loadbalancer-kv-app-activity-success-rule ↳kemp-loadmaster-str-app-activity-l4d
security-alert ↳kemp-loadbalancer-kv-alert-trigger-success-requestcookies
| T1027 - Obfuscated Files or Information T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools T1078 - Valid Accounts T1133 - External Remote Services T1190 - Exploit Public Fasing Application
| |
| Data Access | app-activity ↳kemp-loadbalancer-kv-app-activity-success-rule ↳kemp-loadmaster-str-app-activity-l4d
| T1078 - Valid Accounts
| |
| Data Leak | app-activity ↳kemp-loadbalancer-kv-app-activity-success-rule ↳kemp-loadmaster-str-app-activity-l4d
| T1114 - Email Collection T1114.003 - Email Collection: Email Forwarding Rule
| |
| Lateral Movement | authentication-failed ↳kemp-loadmaster-str-app-authentication-fail-loginfailed
security-alert ↳kemp-loadbalancer-kv-alert-trigger-success-requestcookies
| T1027 - Obfuscated Files or Information T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools T1078 - Valid Accounts T1090 - Proxy T1090.003 - Proxy: Multi-hop Proxy
| |
| Malware | security-alert ↳kemp-loadbalancer-kv-alert-trigger-success-requestcookies
| TA0002 - TA0002
| |
| Privilege Abuse | app-activity ↳kemp-loadbalancer-kv-app-activity-success-rule ↳kemp-loadmaster-str-app-activity-l4d
| T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
| |
| Privilege Escalation | app-activity ↳kemp-loadbalancer-kv-app-activity-success-rule ↳kemp-loadmaster-str-app-activity-l4d
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
| |
| Privileged Activity | app-activity ↳kemp-loadbalancer-kv-app-activity-success-rule ↳kemp-loadmaster-str-app-activity-l4d
security-alert ↳kemp-loadbalancer-kv-alert-trigger-success-requestcookies
| T1068 - Exploitation for Privilege Escalation T1078 - Valid Accounts
| |
| Ransomware | authentication-failed ↳kemp-loadmaster-str-app-authentication-fail-loginfailed
| T1078 - Valid Accounts
| |