Rules by Product and UseCase
December 5, 2023 · View on GitHub
Vendor:
Product:
Use-Case: Phishing
| Rules | Models | MITRE ATT&CK® TTPs | Activity Types | Parsers |
|---|---|---|---|---|
| 5 | 1 | 7 | 4 | 4 |
| Event Type | Rules | Models |
|---|---|---|
| dlp-email-alert-out | T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol ↳ EM-OD-A: Abnormal email domain for organization | • EM-OD: Domains per organization |
| process-created | T1566.001 - T1566.001 ↳ A-Exec-Outlook-Temp: A suspicious program was executed in the Outlook temp folder on this asset. | |
| web-activity-allowed | T1534 - Internal Spearphishing ↳ WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing ↳ A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain. T1566.002 - Phishing: Spearphishing Link ↳ WEB-URank-Binary: Executable download from first low ranked web domain ↳ WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing ↳ A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain. T1598.003 - T1598.003 ↳ WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing ↳ A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain. T1189 - Drive-by Compromise ↳ WEB-URank-Binary: Executable download from first low ranked web domain T1204.001 - T1204.001 ↳ WEB-URank-Binary: Executable download from first low ranked web domain | |
| web-activity-denied | T1534 - Internal Spearphishing ↳ WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing ↳ A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain. T1566.002 - Phishing: Spearphishing Link ↳ WEB-URank-Binary: Executable download from first low ranked web domain ↳ WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing ↳ A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain. T1598.003 - T1598.003 ↳ WEB-UD-Phishing: User attempted to access a domain which is associated to Phishing ↳ A-WEB-Phishing: Asset has accessed a domain suspected to be a phishing domain. T1189 - Drive-by Compromise ↳ WEB-URank-Binary: Executable download from first low ranked web domain T1204.001 - T1204.001 ↳ WEB-URank-Binary: Executable download from first low ranked web domain |