Vendor: SiteMinder

November 29, 2023 · View on GitHub

Product: Symantec SiteMinder

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
48201022
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessapp-login
siteminder-symantecsm-str-app-logout-success-authlogout
T1078 - Valid Accounts
T1133 - External Remote Services
  • 12 Rules
  • 4 Models
Compromised Credentialsapp-login
siteminder-symantecsm-str-app-logout-success-authlogout
T1078 - Valid Accounts
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
  • 27 Rules
  • 16 Models
Data Accessapp-login
siteminder-symantecsm-str-app-logout-success-authlogout
T1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Evasionregistry-write
siteminder-symantecsm-kv-http-request-success-validateaccept
siteminder-symantecsm-kv-http-request-success-azaccept
siteminder-symantecsm-kv-app-activity-azreject
T1564.001 - T1564.001
T1564.002 - T1564.002
  • 2 Rules
Lateral Movementapp-login
siteminder-symantecsm-str-app-logout-success-authlogout
T1090.003 - Proxy: Multi-hop Proxy
  • 1 Rules
Privilege Abuseapp-login
siteminder-symantecsm-str-app-logout-success-authlogout
T1078 - Valid Accounts
  • 2 Rules
Privileged Activityapp-login
siteminder-symantecsm-str-app-logout-success-authlogout
T1078 - Valid Accounts
  • 1 Rules
Ransomwareapp-login
siteminder-symantecsm-str-app-logout-success-authlogout
T1078 - Valid Accounts
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Hijack Execution Flow

Boot or Logon Autostart Execution

Valid Accounts

Hijack Execution Flow

Boot or Logon Autostart Execution

Hide Artifacts

Valid Accounts

Modify Registry

Hijack Execution Flow

Proxy: Multi-hop Proxy

Proxy