| Abnormal Authentication & Access | account-creation ↳sap-s-cef-user-delete-fail-audit
account-deleted ↳sap-s-cef-user-delete-fail-audit
account-lockout ↳sap-s-cef-user-delete-fail-audit
account-unlocked ↳sap-s-cef-user-delete-fail-audit
app-activity ↳sap-s-json-app-activity-success-eventtype ↳sap-s-cef-user-delete-fail-audit
app-login ↳sap-s-json-app-login-success-sm20logon
authentication-failed ↳sap-s-cef-endpoint-authentication-logon
authentication-successful ↳sap-s-cef-endpoint-authentication-logon
| T1078 - Valid Accounts T1110 - Brute Force T1133 - External Remote Services
| |
| Account Manipulation | account-creation ↳sap-s-cef-user-delete-fail-audit
account-deleted ↳sap-s-cef-user-delete-fail-audit
app-activity ↳sap-s-json-app-activity-success-eventtype ↳sap-s-cef-user-delete-fail-audit
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1531 - Account Access Removal
| |
| Brute Force Attack | account-lockout ↳sap-s-cef-user-delete-fail-audit
| T1110 - Brute Force
| |
| Compromised Credentials | app-activity ↳sap-s-json-app-activity-success-eventtype ↳sap-s-cef-user-delete-fail-audit
app-login ↳sap-s-json-app-login-success-sm20logon
authentication-successful ↳sap-s-cef-endpoint-authentication-logon
| T1078 - Valid Accounts T1133 - External Remote Services T1190 - Exploit Public Fasing Application
| |
| Data Access | app-activity ↳sap-s-json-app-activity-success-eventtype ↳sap-s-cef-user-delete-fail-audit
app-login ↳sap-s-json-app-login-success-sm20logon
| T1078 - Valid Accounts
| |
| Data Leak | app-activity ↳sap-s-json-app-activity-success-eventtype ↳sap-s-cef-user-delete-fail-audit
| T1114 - Email Collection T1114.003 - Email Collection: Email Forwarding Rule
| |
| Lateral Movement | app-login ↳sap-s-json-app-login-success-sm20logon
authentication-failed ↳sap-s-cef-endpoint-authentication-logon
authentication-successful ↳sap-s-cef-endpoint-authentication-logon
| T1078 - Valid Accounts T1090 - Proxy T1090.003 - Proxy: Multi-hop Proxy
| |
| Malware | app-login ↳sap-s-json-app-login-success-sm20logon
authentication-successful ↳sap-s-cef-endpoint-authentication-logon
| T1078 - Valid Accounts
| |
| Privilege Escalation | app-activity ↳sap-s-json-app-activity-success-eventtype ↳sap-s-cef-user-delete-fail-audit
| T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
| |
| Privileged Activity | app-activity ↳sap-s-json-app-activity-success-eventtype ↳sap-s-cef-user-delete-fail-audit
app-login ↳sap-s-json-app-login-success-sm20logon
file-download ↳sap-s-cef-file-download-success-auy
| T1078 - Valid Accounts
| |
| Ransomware | app-login ↳sap-s-json-app-login-success-sm20logon
authentication-failed ↳sap-s-cef-endpoint-authentication-logon
authentication-successful ↳sap-s-cef-endpoint-authentication-logon
| T1078 - Valid Accounts
| |
| Next Page -->> | | | |