Rules by Product and UseCase

October 24, 2023 · View on GitHub

Vendor: Apache

Product: Apache

Use-Case: Ransomware

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
10122
Event TypeRulesModels
web-activity-allowedT1071.001 - Application Layer Protocol: Web Protocols
WEB-UI-Ransomware: User attempted to connect to IP address which is associated to Ransomware
web-activity-deniedT1071.001 - Application Layer Protocol: Web Protocols
WEB-UI-Ransomware: User attempted to connect to IP address which is associated to Ransomware