Vendor: Microsoft

November 29, 2023 · View on GitHub

Product: Microsoft CAS

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
16572231010
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-password-change
microsoft-azure-cef-user-password-modify-success-pwdchanged
microsoft-azure-cef-app-authentication-credentialsvalidation
microsoft-mcas-cef-user-password-modify-success-changepassword

app-activity
microsoft-azure-cef-app-file-success-ldapquery
microsoft-mcas-cef-app-activity-success-resolvealert
microsoft-mcas-cef-app-activity-success-updateserviceprincipal
microsoft-mcas-cef-app-activity-success-addpermissiontomailbox
microsoft-mcas-cef-app-activity-success-addmembertogroup
microsoft-mcas-cef-app-activity-success-accessfolder
microsoft-mcas-cef-app-activity-success-msgdelete
microsoft-mcas-cef-app-activity-success-msgsend-1
microsoft-mcas-cef-app-activity-success-agentusercreate
microsoft-mcas-cef-app-activity-success-folderdelete
microsoft-mcas-cef-app-activity-success-msgsend
microsoft-mcas-cef-app-activity-success-foldercreate
microsoft-mcas-cef-app-activity-success-msgupdate
microsoft-mcas-cef-app-activity-success-updateuser
microsoft-mcas-cef-app-activity-success-changeuserlicense
microsoft-mcas-cef-app-activity-success-msgupdate-1
microsoft-mcas-cef-app-activity-success-addmembertorole
microsoft-mcas-cef-app-activity-success-alertdismiss
microsoft-mcas-cef-app-activity-success-movemsgtoanotherfolder
microsoft-mcas-cef-app-activity-success-skyprforbuisnessactivity
microsoft-mcas-cef-app-activity-success-commandrun
microsoft-mcas-cef-app-activity-success-impersonated
microsoft-mcas-cef-app-activity-success-suspiciousemail
microsoft-mcas-cef-app-activity-success-itemcreate
microsoft-mcas-cef-app-activity-success-grantconsoleforthirdparty
microsoft-mcas-cef-app-activity-success-folderrename
microsoft-mcas-cef-app-activity-success-movemsgtodeletedfolder
microsoft-mcas-cef-app-activity-success-msgpurge
microsoft-mcas-cef-app-activity-success-groupsettingchange
microsoft-mcas-cef-app-activity-success-foldermove
microsoft-mcas-cef-app-activity-success-msgdelete-1
microsoft-mcas-cef-app-activity-success-setcompanyinfo

app-login
microsoft-m365auditlogs-sk4-app-activity-mcasactivities
T1078 - Valid Accounts
T1133 - External Remote Services
  • 12 Rules
  • 4 Models
Account Manipulationaccount-password-change
microsoft-azure-cef-user-password-modify-success-pwdchanged
microsoft-azure-cef-app-authentication-credentialsvalidation
microsoft-mcas-cef-user-password-modify-success-changepassword

app-activity
microsoft-azure-cef-app-file-success-ldapquery
microsoft-mcas-cef-app-activity-success-resolvealert
microsoft-mcas-cef-app-activity-success-updateserviceprincipal
microsoft-mcas-cef-app-activity-success-addpermissiontomailbox
microsoft-mcas-cef-app-activity-success-addmembertogroup
microsoft-mcas-cef-app-activity-success-accessfolder
microsoft-mcas-cef-app-activity-success-msgdelete
microsoft-mcas-cef-app-activity-success-msgsend-1
microsoft-mcas-cef-app-activity-success-agentusercreate
microsoft-mcas-cef-app-activity-success-folderdelete
microsoft-mcas-cef-app-activity-success-msgsend
microsoft-mcas-cef-app-activity-success-foldercreate
microsoft-mcas-cef-app-activity-success-msgupdate
microsoft-mcas-cef-app-activity-success-updateuser
microsoft-mcas-cef-app-activity-success-changeuserlicense
microsoft-mcas-cef-app-activity-success-msgupdate-1
microsoft-mcas-cef-app-activity-success-addmembertorole
microsoft-mcas-cef-app-activity-success-alertdismiss
microsoft-mcas-cef-app-activity-success-movemsgtoanotherfolder
microsoft-mcas-cef-app-activity-success-skyprforbuisnessactivity
microsoft-mcas-cef-app-activity-success-commandrun
microsoft-mcas-cef-app-activity-success-impersonated
microsoft-mcas-cef-app-activity-success-suspiciousemail
microsoft-mcas-cef-app-activity-success-itemcreate
microsoft-mcas-cef-app-activity-success-grantconsoleforthirdparty
microsoft-mcas-cef-app-activity-success-folderrename
microsoft-mcas-cef-app-activity-success-movemsgtodeletedfolder
microsoft-mcas-cef-app-activity-success-msgpurge
microsoft-mcas-cef-app-activity-success-groupsettingchange
microsoft-mcas-cef-app-activity-success-foldermove
microsoft-mcas-cef-app-activity-success-msgdelete-1
microsoft-mcas-cef-app-activity-success-setcompanyinfo
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 4 Rules
  • 1 Models
Destruction of Datafile-delete
microsoft-azure-cef-app-file-success-ldapquery
T1070.004 - Indicator Removal on Host: File Deletion
T1485 - Data Destruction
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Server Software Component: Web Shell

Account Manipulation

Server Software Component

Boot or Logon Autostart Execution

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Exploitation for Privilege Escalation

Boot or Logon Autostart Execution

Obfuscated Files or Information: Indicator Removal from Tools

Indicator Removal on Host: File Deletion

Valid Accounts

Indicator Removal on Host

Obfuscated Files or Information

OS Credential Dumping

File and Directory Discovery

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy

Automated Exfiltration

Data Destruction

Data Encrypted for Impact