| Account Manipulation | account-creation ↳unix-auditd-kv-user-create-success-addgroup ↳unix-auditd-kv-user-create-success-adduser
account-deleted ↳unix-auditd-kv-user-delete-success-deleteuser
account-password-change ↳unix-unixauditd-kv-user-password-modify-success-grpmgmt
process-created ↳unix-ad-kv-process-create-success-audit ↳unix-ad-kv-process-create-success-audispd ↳unix-ad-cef-process-create-success-cmd ↳unix-unixauditd-cef-process-create-success-execve ↳unix-unixauditd-cef-process-create-success-syscall ↳unix-unixauditd-cef-process-create-success-usercmd
| T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1136.002 - T1136.002 T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002
| |