Vendor: SecureLink

November 29, 2023 · View on GitHub

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
48201022
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessapp-login
securelink-s-str-app-logout-disconnectedfrom
securelink-s-kv-app-logout-logout
T1078 - Valid Accounts
T1133 - External Remote Services
  • 12 Rules
  • 4 Models
Compromised Credentialsapp-login
securelink-s-str-app-logout-disconnectedfrom
securelink-s-kv-app-logout-logout
T1078 - Valid Accounts
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
  • 27 Rules
  • 16 Models
Data Accessapp-login
securelink-s-str-app-logout-disconnectedfrom
securelink-s-kv-app-logout-logout
T1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Evasionregistry-write
securelink-s-kv-app-activity-appactivity
T1564.001 - T1564.001
T1564.002 - T1564.002
  • 2 Rules
Lateral Movementapp-login
securelink-s-str-app-logout-disconnectedfrom
securelink-s-kv-app-logout-logout
T1090.003 - Proxy: Multi-hop Proxy
  • 1 Rules
Malwareapp-login
securelink-s-str-app-logout-disconnectedfrom
securelink-s-kv-app-logout-logout

registry-write
securelink-s-kv-app-activity-appactivity
T1078 - Valid Accounts
T1112 - Modify Registry
T1547.001 - T1547.001
T1574.010 - T1574.010
T1574.011 - T1574.011
  • 7 Rules
  • 3 Models
Privilege Abuseapp-login
securelink-s-str-app-logout-disconnectedfrom
securelink-s-kv-app-logout-logout
T1078 - Valid Accounts
  • 2 Rules
Privileged Activityapp-login
securelink-s-str-app-logout-disconnectedfrom
securelink-s-kv-app-logout-logout
T1078 - Valid Accounts
  • 1 Rules
Ransomwareapp-login
securelink-s-str-app-logout-disconnectedfrom
securelink-s-kv-app-logout-logout
T1078 - Valid Accounts
  • 1 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Hijack Execution Flow

Boot or Logon Autostart Execution

Valid Accounts

Hijack Execution Flow

Boot or Logon Autostart Execution

Hide Artifacts

Valid Accounts

Modify Registry

Hijack Execution Flow

Proxy: Multi-hop Proxy

Proxy