Rules by Product and UseCase

December 5, 2023 · View on GitHub

Vendor:

Product:

Use-Case: Privileged Activity

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
331582121
Event TypeRulesModels
account-switchT1078 - Valid Accounts
AS-UA-F-PRIV: Account switch to a privileged or executive account
app-activityT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
APP-AT-PRIV: Non-privileged user performing privileged application activity
APP-AT-PRIV: Privileged application activities
app-activity-failedT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
dlp-email-alert-inT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
dlp-email-alert-in-failedT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
dlp-email-alert-outT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
dlp-email-alert-out-failedT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
failed-app-loginT1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
failed-logonT1078 - Valid Accounts
SEQ-UH-12: Logon attempt on a disabled account

T1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
file-alertT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-deleteT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-readT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-uploadT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-writeT1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
privileged-accessTA0002 - TA0002
WPA-UP-F: First privileged process for user
WPA-UP-A: Abnormal privileged process for user
WPA-GP-F: First privileged process for peer group
WPA-GP-A: Abnormal privileged process for peer group
WPA-PD-F: First directory for privileged process
WPA-PD-A: Abnormal directory for privileged process
WPA-HP-F: First privileged process for host
WPA-HP-A: Abnormal privileged process for host
WPA-OP-F: First privileged process for organization
WPA-OP-A: Abnormal privileged process for organization
WPA-OP: Processes for organization
WPA-HP: Processes for host
WPA-PD: Directories per process
WPA-GP: Privileged processes for peer group
WPA-GP-All: Processes for peer group
WPA-UP: Privileged processes for user
WPA-UP-All: Processes for user
process-createdT1482 - Domain Trust Discovery
A-Trickbot-Recon: Trickbot malware domain recon activity on this asset
remote-logonT1078 - Valid Accounts
AL-F-F-CS: First logon to a critical system for user
AL-F-A-CS: Abnormal logon to a critical system for user
AL-UH-CS-NC: Logon to a critical system for a user with no information
AL-OU-F-CS: First logon to a critical system that user has not previously accessed
AL-HT-PRIV: Non-Privileged logon to privileged asset
AL-HT-EXEC-new: New user logon to executive asset

T1021 - Remote Services
RL-UZ-F-DC: First logon to a Domain Controller from zone for user
RL-OZ-F-DC: First logon to a Domain Controller from zone for organization
RL-OZ-A-DC: Abnormal logon to a Domain Controller from zone for organization

T1078.002 - T1078.002
AL-F-F-DC-G: First logon to a Domain Controller for peer group
AL-F-A-DC-G: Abnormal logon to a Domain Controller for Peer Group
AL-UH-F-DC: First logon to this Domain Controller for user
AL-UH-A-DC: Abnormal logon to a Domain Controller that user has not accessed often previously
AL-UH-DC-NC: Logon to a Domain Controller for user with no information
RL-UZ-F-DC: First logon to a Domain Controller from zone for user
RL-OZ-F-DC: First logon to a Domain Controller from zone for organization
RL-OZ-A-DC: Abnormal logon to a Domain Controller from zone for organization

T1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
AL-HT-EXEC: Executive Assets
AL-HT-PRIV: Privilege Users Assets
RL-OZ-DC: Source zones in the organization during domain controller access
RL-UZ-DC: Source zones per user logging into domain controller
RA-UH: Assets accessed by this user remotely
AL-UH-DC: Logons to Domain Controllers
AL-OU-CS: Logon to critical servers
security-alertT1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
web-activity-allowedT1071.001 - Application Layer Protocol: Web Protocols
WEB-ALERT-EXEC: Security violation by Executive in web activity
A-WEB-DC: Web activity event on a Domain Controller

T1102 - Web Service
A-WEB-DC: Web activity event on a Domain Controller

T1078 - Valid Accounts
WEB-ALERT-EXEC: Security violation by Executive in web activity
web-activity-deniedT1071.001 - Application Layer Protocol: Web Protocols
WEB-ALERT-EXEC: Security violation by Executive in web activity
A-WEB-DC: Web activity event on a Domain Controller

T1102 - Web Service
A-WEB-DC: Web activity event on a Domain Controller

T1078 - Valid Accounts
WEB-ALERT-EXEC: Security violation by Executive in web activity