Rules by Product and UseCase

April 15, 2026 · View on GitHub

Vendor: SecureNet

Product: SecureNet

Use-Case: Account Manipulation

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
77310
Event TypeRulesModels
vpn-logoutT1484 - Group Policy Modification
FDS-Count: Abnormal number of failed directory service events in the organization
FDS-GCount: Abnormal number of failed directory service events in the peer group
FDS-UCount: Abnormal number of failed directory service events in the user
DS-Count: Abnormal number of directory service events in the organization
DS-GCount: Abnormal number of directory service events in the peer group
DS-UCount: Abnormal number of directory service events in the user

T1098 - Account Manipulation
EM-InB-Perm-A: Abnormal number of mailbox permission given by user.

T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
EM-InB-Perm-A: Abnormal number of mailbox permission given by user.
DS-UCount: Count of directory service activity events in the user
DS-GCount: Count of directory service activity events in the peer group
DS-Count: Count of directory service activity events in the organization
FDS-UCount: Count of failed directory service activity events in the user
FDS-GCount: Count of failed directory service activity events in the peer group
FDS-Count: Count of failed directory service activity events in the organization
EM-InB-Perm: Models the number of mailbox permissions given by this user.