Vendor: SAP

December 5, 2023 · View on GitHub

Product: SAP

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
17470291212
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-creation
sap-s-cef-user-create-success-created

account-deleted
sap-s-cef-user-delete-success-deleted

account-lockout
sap-s-cef-user-lock-success-locked

account-password-change
sap-s-cef-user-password-modify-success-changed
sap-s-cef-user-password-modify-success-loginforsso

account-unlocked
sap-s-cef-user-unlock-success-unlocked

app-login
sap-s-kv-network-session-functioncall
sap-s-cef-network-session-rfccallsuccess
sap-s-cef-app-login-success-dialoglogonsuccessful

authentication-failed
sap-s-cef-endpoint-login-fail-secude

authentication-successful
sap-s-cef-endpoint-login-success-assertion-1
sap-s-cef-endpoint-login-success-assertion

failed-app-login
sap-s-cef-app-login-fail-dialoglogonfailed

remote-logon
sap-s-cef-app-logout-userlogoff
sap-s-cef-app-notification-success-attribute
sap-s-cef-app-notification-accessbyrfc
sap-s-cef-app-notification-success-cbus
sap-s-cef-app-notification-transactionstarted
sap-s-cef-app-notification-success-bul
sap-s-cef-app-notification-transactionfailed
sap-s-cef-app-notification-success-nameid
sap-s-cef-app-notification-reportstarted
sap-s-cef-app-notification-success-bu4
sap-s-cef-app-notification-messagecu1
sap-s-cef-app-notification-success-e00
sap-s-cef-app-notification-success-h01
sap-s-cef-app-notification-success-bi0
sap-s-cef-app-notification-success-duz
sap-s-cef-app-notification-success-eg0
sap-s-cef-app-notification-success-cub
sap-s-cef-app-notification-success-aud
sap-s-cef-app-notification-success-geo
sap-s-cef-endpoint-login-fail-cpiclogonfail
sap-s-cef-endpoint-login-success-cpiclogonsuccessful
T1021 - Remote Services
T1078 - Valid Accounts
T1078.002 - T1078.002
T1078.003 - Valid Accounts: Local Accounts
T1110 - Brute Force
T1133 - External Remote Services
  • 36 Rules
  • 14 Models
Account Manipulationaccount-creation
sap-s-cef-user-create-success-created

account-deleted
sap-s-cef-user-delete-success-deleted

account-password-change
sap-s-cef-user-password-modify-success-changed
sap-s-cef-user-password-modify-success-loginforsso
T1098 - Account Manipulation
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
T1531 - Account Access Removal
  • 22 Rules
  • 8 Models
Brute Force Attackaccount-lockout
sap-s-cef-user-lock-success-locked
T1110 - Brute Force
  • 1 Rules
Data Exfiltrationfile-write
sap-s-cef-file-write-success-download
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Data Leakfile-write
sap-s-cef-file-write-success-download
T1114.001 - T1114.001
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

Create Account

External Remote Services

Valid Accounts

Server Software Component: Web Shell

Account Manipulation

Server Software Component

Boot or Logon Autostart Execution

Create Account: Create: Local Account

Valid Accounts

Exploitation for Privilege Escalation

Boot or Logon Autostart Execution

Valid Accounts

Use Alternate Authentication Material

Use Alternate Authentication Material: Pass the Hash

Use Alternate Authentication Material: Pass the Ticket

Valid Accounts: Local Accounts

OS Credential Dumping

Brute Force

Steal or Forge Kerberos Tickets

Credentials from Password Stores

Steal or Forge Kerberos Tickets: Kerberoasting

File and Directory Discovery

Remote System Discovery

Remote Services

Use Alternate Authentication Material

Email Collection

Proxy: Multi-hop Proxy

Proxy

Account Access Removal

Data Encrypted for Impact