Rules by Product and UseCase

April 15, 2026 · View on GitHub

Vendor: PostgreSQL

Product: PostgreSQL

Use-Case: Compromised Credentials

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
1810122
Event TypeRulesModels
database-loginT1213 - Data from Information Repositories
DB-DbU-F: First access to database for user
DB-DbU-A: Abnormal access to database for user
DB-DbG-F: First access to database for peer group
DB-DbG-A: Abnormal access to database for peer group
DB-UDbZ-F: First database activity from source zone per user, database
DB-UDbZ-A: Abnormal database activity from source zone per user, database
DB-UDbH-F: First database activity from host per user, database
DB-UDbH-A: Abnormal database activity from host per user, database
DB-UDbI-F: First database activity from IP per user, database
DB-UDbI-A: Abnormal database activity from IP per user, database
DB-UDbI: Database activity from source IP per user, database
DB-UDbH: Database activity from host per user, database
DB-UDbZ: Database activity from source zone per user, database
DB-DbG: Peer groups per database
DB-DbU: Users per database
database-queryT1213 - Data from Information Repositories
DB-DbU-F: First access to database for user
DB-DbU-A: Abnormal access to database for user
DB-DbG-F: First access to database for peer group
DB-DbG-A: Abnormal access to database for peer group
DB-UDbZ-F: First database activity from source zone per user, database
DB-UDbZ-A: Abnormal database activity from source zone per user, database
DB-UDbH-F: First database activity from host per user, database
DB-UDbH-A: Abnormal database activity from host per user, database
DB-UDbI-F: First database activity from IP per user, database
DB-UDbI-A: Abnormal database activity from IP per user, database
DB-UDbO-F: First database operation for user, database
DB-UDbO-A: Abnormal database operation for user, database
DB-GDbO-F: First database operation for peer group, database
DB-GDbO-A: Abnormal database operation for peer group, database
DB-DbZO-F: First database operation from source zone for database
DB-DbZO-A: Abnormal database operation from source zone for database
DB-UDbR: Abnormal database query response size for user, database
DB-DbZR: Abnormal database query response size for source zone, database
DB-DbZR: Response size of database queries per zone, database
DB-UDbR: Response size of database queries per user, database
DB-DbZO: Database operations per database, source zone
DB-GDbO: Database operations per peer group, database
DB-UDbO: Database operations per user, database
DB-UDbI: Database activity from source IP per user, database
DB-UDbH: Database activity from host per user, database
DB-UDbZ: Database activity from source zone per user, database
DB-DbG: Peer groups per database
DB-DbU: Users per database