Rules by Product and UseCase

December 5, 2023 · View on GitHub

Vendor:

Product:

Use-Case: Phishing

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
51744
Event TypeRulesModels
dlp-email-alert-outT1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
EM-OD-A: Abnormal email domain for organization
EM-OD: Domains per organization
process-createdT1566.001 - T1566.001
A-Exec-Outlook-Temp: A suspicious program was executed in the Outlook temp folder on this asset.
web-activity-allowedT1534 - Internal Spearphishing
WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing
A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain.

T1566.002 - Phishing: Spearphishing Link
WEB-URank-Binary: Executable download from first low ranked web domain
WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing
A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain.

T1598.003 - T1598.003
WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing
A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain.

T1189 - Drive-by Compromise
WEB-URank-Binary: Executable download from first low ranked web domain

T1204.001 - T1204.001
WEB-URank-Binary: Executable download from first low ranked web domain
web-activity-deniedT1534 - Internal Spearphishing
WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing
A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain.

T1566.002 - Phishing: Spearphishing Link
WEB-URank-Binary: Executable download from first low ranked web domain
WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing
A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain.

T1598.003 - T1598.003
WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing
A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain.

T1189 - Drive-by Compromise
WEB-URank-Binary: Executable download from first low ranked web domain

T1204.001 - T1204.001
WEB-URank-Binary: Executable download from first low ranked web domain