Vendor: Trellix

April 15, 2026 · View on GitHub

Product: Trellix Database Security

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
4021221
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Compromised Credentialsdatabase-alert
mcafee-mdam-cef-alert-trigger-success-alert-1
mcafee-mdam-cef-alert-trigger-success-alert-1

database-query
mcafee-mdam-kv-database-dbactivity
T1213 - Data from Information Repositories
  • 36 Rules
  • 19 Models
Data Accessdatabase-alert
mcafee-mdam-cef-alert-trigger-success-alert-1
mcafee-mdam-cef-alert-trigger-success-alert-1

database-query
mcafee-mdam-kv-database-dbactivity
T1213 - Data from Information Repositories
  • 36 Rules
  • 19 Models
Data Exfiltrationdatabase-alert
mcafee-mdam-cef-alert-trigger-success-alert-1
mcafee-mdam-cef-alert-trigger-success-alert-1
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Malwaredatabase-alert
mcafee-mdam-cef-alert-trigger-success-alert-1
mcafee-mdam-cef-alert-trigger-success-alert-1
TA0002 - TA0002
  • 2 Rules
  • 1 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Data from Information Repositories