Rules by Product and UseCase

September 3, 2025 · View on GitHub

Vendor: Unix

Product: Auditbeat

Use-Case: Data Leak

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
10211
Event TypeRulesModels
file-writeT1114 - Email Collection
FA-Outlook-pst: A file ends with either pst or ost

T1114.001 - T1114.001
FA-Outlook-pst: A file ends with either pst or ost