Vendor: VMware

October 24, 2023 · View on GitHub

Product: VMware AirWatch

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
111441155
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessapp-activity
vmware-airwatch-kv-app-logout-success-userloggedout
vmware-airwatch-kv-app-activity-success-wiperequest
vmware-airwatch-kv-app-activity-success-appremoved
vmware-airwatch-kv-app-activity-success-deleterequest
vmware-airwatch-kv-app-activity-success-wiperequested-1
vmware-airwatch-kv-app-activity-success-exitlauncher
vmware-airwatch-kv-app-activity-success-smartgroups
vmware-airwatch-kv-app-activity-success-applications
vmware-airwatch-kv-app-activity-success-profiles
vmware-airwatch-kv-app-activity-success-authentication
vmware-airwatch-kv-app-activity-success-wiperequested
vmware-airwatch-kv-app-activity-success-device
vmware-airwatch-kv-app-activity-success-tokenrevoked
vmware-airwatch-kv-app-activity-success-breakmdmr
vmware-airwatch-kv-certificate-expire-success-revoked
vmware-airwatch-kv-group-delete-success-groupdeleted
vmware-airwatch-kv-user-delete-success-userdeleted
vmware-airwatch-kv-user-delete-success-profiledeleted
vmware-airwatch-kv-user-disable-success-profileinactivated
vmware-airwatch-kv-user-modify-success-profilemodified

authentication-failed
vmware-airwatch-kv-endpoint-login-fail-loginfailed

authentication-successful
vmware-airwatch-kv-endpoint-login-success-adminuserlogin
vmware-airwatch-kv-endpoint-login-success-adminuserloggedin
T1078 - Valid Accounts
T1133 - External Remote Services
  • 15 Rules
  • 4 Models
Account Manipulationapp-activity
vmware-airwatch-kv-app-logout-success-userloggedout
vmware-airwatch-kv-app-activity-success-wiperequest
vmware-airwatch-kv-app-activity-success-appremoved
vmware-airwatch-kv-app-activity-success-deleterequest
vmware-airwatch-kv-app-activity-success-wiperequested-1
vmware-airwatch-kv-app-activity-success-exitlauncher
vmware-airwatch-kv-app-activity-success-smartgroups
vmware-airwatch-kv-app-activity-success-applications
vmware-airwatch-kv-app-activity-success-profiles
vmware-airwatch-kv-app-activity-success-authentication
vmware-airwatch-kv-app-activity-success-wiperequested
vmware-airwatch-kv-app-activity-success-device
vmware-airwatch-kv-app-activity-success-tokenrevoked
vmware-airwatch-kv-app-activity-success-breakmdmr
vmware-airwatch-kv-certificate-expire-success-revoked
vmware-airwatch-kv-group-delete-success-groupdeleted
vmware-airwatch-kv-user-delete-success-userdeleted
vmware-airwatch-kv-user-delete-success-profiledeleted
vmware-airwatch-kv-user-disable-success-profileinactivated
vmware-airwatch-kv-user-modify-success-profilemodified
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 3 Rules
  • 1 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Account Manipulation

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Exploitation for Privilege Escalation

Obfuscated Files or Information: Indicator Removal from Tools

Valid Accounts

Obfuscated Files or Information

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy