Use Case: Workforce Protection
May 13, 2026 · View on GitHub
Use Case: Workforce Protection
Vendor: Accellion
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Kiteworks | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Adobe
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Adobe Experience Manager | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Akamai
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Akamai SIEM | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Cloud Akamai | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Amazon
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| AWS CloudWatch | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| AWS Elastic Load Balancer | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| AWS Simple Email Service | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| AWS WAF | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Amazon S3 | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Apache
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Apache | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Armorblox
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Armorblox | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Auth0
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Auth0 | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Barracuda
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Barracuda Email Security Gateway | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: BeyondTrust
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| BeyondTrust Remote Support | T1078 - Valid Accounts T1078.004 - Valid Accounts: Cloud Accounts |
|
Vendor: Bitglass
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Bitglass CASB | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: CatoNetworks
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Cato Cloud | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Check Point
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Check Point Avanan | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Check Point NGFW | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Cisco
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Cisco Cloud Security | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Cisco Email Security | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Cisco Network Security | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Cisco Web Security | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Citrix
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Citrix Gateway | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Cloudflare
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Cloudflare Insights | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Cloudflare WAF | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Darktrace
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Darktrace | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Dell
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Sonicwall | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Digital Arts
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Digital Arts i-FILTER for Business | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Digital Guardian
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Digital Guardian Network DLP | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: F5
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| F5 Distributed Cloud | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| F5 WebSafe | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Forcepoint
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Forcepoint DLP | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Forcepoint Email Security | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Websense Security Gateway | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Fortinet
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| FortiClient | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| FortiGate | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| FortiSIEM | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Fortinet Enterprise Firewall | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Fortinet UTM | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Fortiweb Web Application Firewall | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Google
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| GCP CloudAudit | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Google Cloud Platform | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Google Workspace | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: HUMAN Security
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| HUMAN Bot Defender | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Hornet
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Hornetsecurity Cloud Email Security Services | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: IBM
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Security Access Manager | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: IMSVA
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| IMSVA | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Imperva
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Imperva Incapsula | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Infoblox
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| BloxOne DDI | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Island
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Island Enterprise Browser | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Ivanti
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Ivanti Pulse Secure | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Kasada
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Kasada | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Kong
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Kong Gateway | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: LanScope
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| LanScope Cat | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Libraesva
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Libraesva Email Security | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: LogRhythm
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| LogRhythm | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: McAfee
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| McAfee Web Gateway | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Menlo Security
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Menlo Security | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Microsoft
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Active Directory Federation Services | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Azure Monitor | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Event Viewer - ADFS | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Event Viewer - Security | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| M365 Audit Logs | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| MSSQL | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Microsoft 365 | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Microsoft CAS | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Microsoft Defender | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Microsoft Exchange | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Microsoft IIS | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Mimecast
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Code42 Incydr | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Mimecast Secure Email Gateway | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Mimecast Targeted Threat Protection - URL | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Netskope
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Netskope Security Cloud | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Netskope Webtx | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: NextDLP
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Reveal | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Palo Alto Networks
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Palo Alto NGFW | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Prisma Access | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Prisma Cloud | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Ping Identity
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| ForgeRock | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Ping Access | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Postfix
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Postfix | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Proofpoint
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Proofpoint Email Protection | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Proofpoint Enterprise Protection | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Targeted Attack Platform | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: SIGSCI
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| SIGSCI | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Salesforce
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Salesforce | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Sangfor
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Sangfor NGAF | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: SentinelOne
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Singularity Platform | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: ServiceNow
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| ServiceNow | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: SkySea
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| SkySea ClientView | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Skyhigh Security
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Secure Web Gateway | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Skyhigh Security Cloud | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Sophos
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Sophos UTM | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Sophos XG Firewall | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Squid
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Squid | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Symantec
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Symantec DLP | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Symantec Email Security | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Symantec Web Security Service | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Tessian
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Tessian Cloud Email Security | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Trellix
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Trellix Network Security (NX) | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Unix
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Unix | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
| Unix Sendmail | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
|
Vendor: Watchguard
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Watchguard | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Zeek
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Zeek | T1048 - Exfiltration Over Alternative Protocol T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor: Zoom
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Zoom | T1078 - Valid Accounts T1078.004 - Valid Accounts: Cloud Accounts T1090 - Proxy T1090.003 - Proxy: Multi-hop Proxy T1098 - Account Manipulation |
|
Vendor: Zscaler
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Zscaler Breach Predictor | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Zscaler Internet Access | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
| Zscaler Private Access | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|
Vendor:
Vendor: iBoss
| Product | MITRE ATT&CK® TTP | Content |
|---|---|---|
| Iboss Cloud | T1071 - Application Layer Protocol T1071.001 - Application Layer Protocol: Web Protocols |
|