Vendor: IBM

November 29, 2023 · View on GitHub

Product: HCL Notes

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
4420722
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessauthentication-failed
ibm-hclnotes-str-app-notification-success-agent
ibm-hclnotes-str-app-notification-success-locate
ibm-hclnotes-str-message-send-success-delivered
ibm-hclnotes-str-network-close-success-disconnected
ibm-hclnotes-str-file-upload-success-pushing
ibm-hclnotes-str-file-download-success-pulling
ibm-hclnotes-str-file-write-success-added
ibm-hclnotes-str-file-write-success-updated
T1133 - External Remote Services
  • 3 Rules
  • 3 Models
Lateral Movementauthentication-failed
ibm-hclnotes-str-app-notification-success-agent
ibm-hclnotes-str-app-notification-success-locate
ibm-hclnotes-str-message-send-success-delivered
ibm-hclnotes-str-network-close-success-disconnected
ibm-hclnotes-str-file-upload-success-pushing
ibm-hclnotes-str-file-download-success-pulling
ibm-hclnotes-str-file-write-success-added
ibm-hclnotes-str-file-write-success-updated

network-connection-successful
ibm-ln-str-network-traffic-success-connected
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
T1190 - Exploit Public Fasing Application
TA0010 - TA0010
TA0011 - TA0011
  • 40 Rules
  • 17 Models
Malwarenetwork-connection-successful
ibm-ln-str-network-traffic-success-connected
TA0011 - TA0011
  • 3 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Valid Accounts

Valid Accounts

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy