Rules by Product and UseCase

April 15, 2026 · View on GitHub

Use-Case: Account Manipulation

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
41231
Event TypeRulesModels
account-password-changeT1098 - Account Manipulation
AM-UA-APLocU-F: First account password change for local user
account-password-resetT1098 - Account Manipulation
AM-UA-APLocU-F: First account password change for local user
app-activityT1098 - Account Manipulation
EM-InB-Ex: A user has been given mailbox permissions for an executive user
EM-InB-Perm-N-F: First time a user has given mailbox permissions on another mailbox that is not their own
EM-InB-Perm-N-A: Abnormal for user to give mailbox permissions

T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
EM-InB-Ex: A user has been given mailbox permissions for an executive user
EM-InB-Perm-N-F: First time a user has given mailbox permissions on another mailbox that is not their own
EM-InB-Perm-N-A: Abnormal for user to give mailbox permissions
EM-InB-Perm-N: Models users who give mailbox permissions