Rules by Product and UseCase

November 29, 2023 · View on GitHub

Vendor: GitHub

Product: GitHub

Use-Case: Malware

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
40233
Event TypeRulesModels
app-activityT1078 - Valid Accounts
Auth-Blacklist-Shost: User authentication or login from a known blacklisted IP
authentication-successfulT1078 - Valid Accounts
Auth-Blacklist-Shost: User authentication or login from a known blacklisted IP
network-connection-successfulTA0011 - TA0011
A-NET-TI-H-Outbound: Outbound connection to a known malicious host
A-NET-TI-IP-Inbound: Inbound connection from a known malicious IP
A-NET-TI-H-Inbound: Inbound connection from a known malicious host