Use Case: Data Access

December 5, 2023 · View on GitHub

Use Case: Data Access

Vendor: AMD

ProductMITRE ATT&CK® TTPContent
PensandoT1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models

Vendor: AVI Networks

ProductMITRE ATT&CK® TTPContent
AVI Networks Software Load BalancerT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Absolute

ProductMITRE ATT&CK® TTPContent
Absolute DDST1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: Accellion

ProductMITRE ATT&CK® TTPContent
KiteworksT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: Airlock

ProductMITRE ATT&CK® TTPContent
Airlock AllowlistingT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Airlock Security Access HubT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 30 Rules
  • 17 Models

Vendor: Amazon

ProductMITRE ATT&CK® TTPContent
AWS CloudTrailT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models
AWS GuardDutyT1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models
AWS RedshiftT1213 - Data from Information Repositories
  • 18 Rules
  • 10 Models
Amazon EKST1003 - OS Credential Dumping
  • 1 Rules
Amazon RDST1003 - OS Credential Dumping
T1213 - Data from Information Repositories
  • 19 Rules
  • 10 Models

Vendor: Apache

ProductMITRE ATT&CK® TTPContent
Apache SubversionT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: AssetView

ProductMITRE ATT&CK® TTPContent
AssetViewT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: Atlassian

ProductMITRE ATT&CK® TTPContent
Atlassian BitBucketT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: Auth0

ProductMITRE ATT&CK® TTPContent
Auth0T1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Banyan Security

ProductMITRE ATT&CK® TTPContent
Banyan SecurityT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Barracuda

ProductMITRE ATT&CK® TTPContent
Barracuda Cloudgen FirewallT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Barracuda Email Security GatewayT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Barracuda WAFT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: BeyondTrust

ProductMITRE ATT&CK® TTPContent
BeyondInsightT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 31 Rules
  • 16 Models
BeyondTrustT1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 20 Rules
  • 11 Models
BeyondTrust Privileged IdentityT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
BeyondTrust Secure Remote AccessT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: Bitdefender

ProductMITRE ATT&CK® TTPContent
GravityZoneT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Bitglass

ProductMITRE ATT&CK® TTPContent
Bitglass CASBT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Box

ProductMITRE ATT&CK® TTPContent
Box Cloud Content ManagementT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Broadcom

ProductMITRE ATT&CK® TTPContent
z/OST1078 - Valid Accounts
  • 1 Rules

Vendor: CA Technologies

ProductMITRE ATT&CK® TTPContent
CA Privileged Access Manager Server ControlT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Check Point

ProductMITRE ATT&CK® TTPContent
Check Point Endpoint SecurityT1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models
Check Point NGFWT1078 - Valid Accounts
T1110 - Brute Force
T1213 - Data from Information Repositories
  • 30 Rules
  • 17 Models
Check Point Security GatewayT1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Cisco

ProductMITRE ATT&CK® TTPContent
AnyConnectT1110 - Brute Force
  • 1 Rules
  • 1 Models
CiscoT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Cisco ACST1003 - OS Credential Dumping
  • 1 Rules
Cisco Adaptive Security ApplianceT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1110 - Brute Force
  • 21 Rules
  • 12 Models
Cisco FirepowerT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1110 - Brute Force
  • 21 Rules
  • 12 Models
Cisco IOST1003 - OS Credential Dumping
  • 1 Rules
Cisco ISET1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Cisco Meraki MX applianceT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Cisco Secure EndpointT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Cisco Unified Communications ManagerT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Duo AccessT1078 - Valid Accounts
  • 20 Rules
  • 11 Models
IronPort EmailT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Citrix

ProductMITRE ATT&CK® TTPContent
Citrix GatewayT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1110 - Brute Force
  • 21 Rules
  • 12 Models
Citrix ShareFileT1078 - Valid Accounts
  • 20 Rules
  • 11 Models
Citrix Virtual AppsT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Clearsense

ProductMITRE ATT&CK® TTPContent
ClearsenseT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Click Studios

ProductMITRE ATT&CK® TTPContent
PasswordstateT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: Cloudflare

ProductMITRE ATT&CK® TTPContent
Cloudflare InsightsT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: Code42

ProductMITRE ATT&CK® TTPContent
Code42 IncydrT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 43 Rules
  • 24 Models

Vendor: Cohesity

ProductMITRE ATT&CK® TTPContent
Cohesity DataPlatformT1003 - OS Credential Dumping
  • 1 Rules

Vendor: CrowdStrike

ProductMITRE ATT&CK® TTPContent
FalconT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 45 Rules
  • 24 Models

Vendor: CyberArk

ProductMITRE ATT&CK® TTPContent
CyberArk Privilege Access ManagerT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: Cylance

ProductMITRE ATT&CK® TTPContent
Cylance OPTICST1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Cylance PROTECTT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Darktrace

ProductMITRE ATT&CK® TTPContent
DarktraceT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Delinea

ProductMITRE ATT&CK® TTPContent
Centrify Infrastructure ServicesT1003 - OS Credential Dumping
  • 1 Rules
Centrify Zero Trust Privilege ServicesT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: Dell

ProductMITRE ATT&CK® TTPContent
EMC IsilonT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models
SonicwallT1078 - Valid Accounts
T1110 - Brute Force
  • 6 Rules
  • 5 Models

Vendor: Digital Guardian

ProductMITRE ATT&CK® TTPContent
Digital Guardian Endpoint ProtectionT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: Dropbox

ProductMITRE ATT&CK® TTPContent
DropboxT1078 - Valid Accounts
T1083 - File and Directory Discovery
T1110 - Brute Force
  • 44 Rules
  • 25 Models

Vendor: Dtex Systems

ProductMITRE ATT&CK® TTPContent
DTEX InTERCEPTT1003 - OS Credential Dumping
  • 1 Rules

Vendor: ESET

ProductMITRE ATT&CK® TTPContent
ESET Endpoint SecurityT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: ESector

ProductMITRE ATT&CK® TTPContent
ESector DEFESA LoggerT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: Epic

ProductMITRE ATT&CK® TTPContent
Epic SIEMT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: Exabeam

ProductMITRE ATT&CK® TTPContent
Audit LogT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 43 Rules
  • 24 Models
SearchT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: Extreme Networks

ProductMITRE ATT&CK® TTPContent
Zebra WLAN ManagementT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: F5

ProductMITRE ATT&CK® TTPContent
F5 Access Policy ManagerT1110 - Brute Force
  • 1 Rules
  • 1 Models
F5 Advanced Web Application FirewallT1003 - OS Credential Dumping
  • 1 Rules
F5 BIG-IPT1078 - Valid Accounts
T1110 - Brute Force
  • 20 Rules
  • 12 Models
F5 BIG-IP DNST1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: FTP

ProductMITRE ATT&CK® TTPContent
FTPT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: FileAuditor

ProductMITRE ATT&CK® TTPContent
FileAuditorT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: Forcepoint

ProductMITRE ATT&CK® TTPContent
Forcepoint CASBT1078 - Valid Accounts
  • 1 Rules

Vendor: Fortinet

ProductMITRE ATT&CK® TTPContent
FortiGateT1110 - Brute Force
  • 1 Rules
  • 1 Models
Fortinet UTMT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: GitHub

ProductMITRE ATT&CK® TTPContent
GitHubT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: GoAnywhere

ProductMITRE ATT&CK® TTPContent
GoAnywhere MFTT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: Google

ProductMITRE ATT&CK® TTPContent
Google Cloud PlatformT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 37 Rules
  • 21 Models
Google WorkspaceT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: HP

ProductMITRE ATT&CK® TTPContent
Aruba ClearPass Policy ManagerT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
HP iLOT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
HPE ComwareT1003 - OS Credential Dumping
T1083 - File and Directory Discovery
  • 25 Rules
  • 13 Models

Vendor: HashiCorp

ProductMITRE ATT&CK® TTPContent
HashiCorp VaultT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: HelpSystems

ProductMITRE ATT&CK® TTPContent
Powertech Identity and Access ManagerT1003 - OS Credential Dumping
  • 1 Rules

Vendor: Huawei

ProductMITRE ATT&CK® TTPContent
Huawei Unified Security GatewayT1003 - OS Credential Dumping
  • 1 Rules

Vendor: IBM

ProductMITRE ATT&CK® TTPContent
GuardiumT1213 - Data from Information Repositories
  • 18 Rules
  • 10 Models
IBM MainframeT1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 7 Rules
  • 4 Models
IBM Resource Access Control FacilityT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 30 Rules
  • 16 Models
Sterling B2B IntegratorT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Imperva

ProductMITRE ATT&CK® TTPContent
Imperva SecureSphereT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 23 Rules
  • 14 Models

Vendor: Imprivata

ProductMITRE ATT&CK® TTPContent
ImprivataT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: InfoWatch

ProductMITRE ATT&CK® TTPContent
InfoWatch DLPT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Infoblox

ProductMITRE ATT&CK® TTPContent
BloxOne DDIT1003 - OS Credential Dumping
T1083 - File and Directory Discovery
  • 25 Rules
  • 13 Models
Infoblox NIOST1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Ipswitch

ProductMITRE ATT&CK® TTPContent
MoveIt TransferT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: Ivanti

ProductMITRE ATT&CK® TTPContent
Ivanti Pulse SecureT1078 - Valid Accounts
T1110 - Brute Force
  • 20 Rules
  • 12 Models

Vendor: Jumpcloud

ProductMITRE ATT&CK® TTPContent
JumpcloudT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Juniper Networks

ProductMITRE ATT&CK® TTPContent
Juniper SRX SeriesT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Junos OST1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Kemp

ProductMITRE ATT&CK® TTPContent
Kemp LoadMasterT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: LanScope

ProductMITRE ATT&CK® TTPContent
LanScope CatT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: LastPass

ProductMITRE ATT&CK® TTPContent
LastPassT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: Lenel

ProductMITRE ATT&CK® TTPContent
OnGuardT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: LiquidFiles

ProductMITRE ATT&CK® TTPContent
LiquidFilesT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: LogRhythm

ProductMITRE ATT&CK® TTPContent
LogRhythmT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: ManageEngine

ProductMITRE ATT&CK® TTPContent
ADAuditPlusT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
ADSSPT1078 - Valid Accounts
  • 20 Rules
  • 11 Models
PAM360T1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: MariaDB

ProductMITRE ATT&CK® TTPContent
MariaDBT1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models

Vendor: MasterSAM

ProductMITRE ATT&CK® TTPContent
MasterSAM PAMT1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models

Vendor: McAfee

ProductMITRE ATT&CK® TTPContent
McAfee DAMT1213 - Data from Information Repositories
  • 30 Rules
  • 16 Models
McAfee Endpoint SecurityT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models
McAfee Network Security PlatformT1078 - Valid Accounts
  • 6 Rules
  • 4 Models
Skyhigh Networks CASBT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: Microsoft

ProductMITRE ATT&CK® TTPContent
AzureT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Azure AD Activity LogsT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 37 Rules
  • 21 Models
Azure AD Sign-In LogsT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Azure ATPT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 23 Rules
  • 14 Models
Azure Event HubT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models
Azure MFAT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Azure MonitorT1078 - Valid Accounts
T1083 - File and Directory Discovery
T1213 - Data from Information Repositories
  • 61 Rules
  • 34 Models
Azure Monitor - VM InsightsT1003 - OS Credential Dumping
  • 1 Rules
Event Viewer - ADFST1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Event Viewer - ApplicationT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Event Viewer - ApplockerT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Event Viewer - AzureADPasswordProtection-DCAgentT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models
Event Viewer - DHCP-ServerT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 30 Rules
  • 16 Models
Event Viewer - DNSServerT1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 6 Rules
  • 4 Models
Event Viewer - PowerShellT1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 6 Rules
  • 4 Models
Event Viewer - SecurityT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
T1110 - Brute Force
T1213 - Data from Information Repositories
  • 55 Rules
  • 30 Models
Event Viewer - SystemT1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 20 Rules
  • 11 Models
Event Viewer - TaskSchedulerT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Event Viewer - TerminalServices-GatewayT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Event Viewer - TerminalServices-LocalSessionManagerT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
M365 Audit LogsT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
MSSQLT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 24 Rules
  • 14 Models
Microsoft 365T1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 45 Rules
  • 24 Models
Microsoft Advanced Threat AnalyticsT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Microsoft CAST1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 43 Rules
  • 24 Models
Microsoft DHCP LogT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 25 Rules
  • 13 Models
Microsoft Defender for CloudT1213 - Data from Information Repositories
  • 30 Rules
  • 16 Models
Microsoft Defender for EndpointT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 30 Rules
  • 17 Models
Microsoft ExchangeT1078 - Valid Accounts
  • 20 Rules
  • 11 Models
Microsoft IntuneT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Microsoft WMI LogT1003 - OS Credential Dumping
  • 1 Rules
SysmonT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models
WindowsT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Windows Defender Application ControlT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: Mimecast

ProductMITRE ATT&CK® TTPContent
Mimecast Secure Email GatewayT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: Mysql

ProductMITRE ATT&CK® TTPContent
MysqlT1213 - Data from Information Repositories
  • 18 Rules
  • 10 Models

Vendor: NCP

ProductMITRE ATT&CK® TTPContent
NCPT1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: NNT

ProductMITRE ATT&CK® TTPContent
NNT ChangeTrackerT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Nasuni

ProductMITRE ATT&CK® TTPContent
NasuniT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: NetApp

ProductMITRE ATT&CK® TTPContent
NetAppT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 29 Rules
  • 17 Models

Vendor: NetIQ

ProductMITRE ATT&CK® TTPContent
Micro Focus NetIQ Identity ManagerT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Netskope

ProductMITRE ATT&CK® TTPContent
Netskope Security CloudT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: Netwrix

ProductMITRE ATT&CK® TTPContent
Netwrix AuditorT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: NextDLP

ProductMITRE ATT&CK® TTPContent
RevealT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: Nortel Contivity

ProductMITRE ATT&CK® TTPContent
Nortel Contivity VPNT1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Nutanix

ProductMITRE ATT&CK® TTPContent
Nutanix Unified StorageT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models

Vendor: Okta

ProductMITRE ATT&CK® TTPContent
Okta Adaptive MFAT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: OneLogin

ProductMITRE ATT&CK® TTPContent
OneLoginT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: OneWelcome

ProductMITRE ATT&CK® TTPContent
OneWelcome Cloud Identity PlatformT1003 - OS Credential Dumping
  • 1 Rules

Vendor: Open VPN

ProductMITRE ATT&CK® TTPContent
Open VPNT1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Oracle

ProductMITRE ATT&CK® TTPContent
Oracle Access ManagementT1078 - Valid Accounts
  • 6 Rules
  • 4 Models
Oracle DatabaseT1213 - Data from Information Repositories
  • 18 Rules
  • 10 Models
Oracle Public CloudT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 30 Rules
  • 16 Models

Vendor: Osquery

ProductMITRE ATT&CK® TTPContent
OsqueryT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 37 Rules
  • 21 Models

Vendor: Palo Alto Networks

ProductMITRE ATT&CK® TTPContent
Cortex XDRT1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models
GlobalProtectT1078 - Valid Accounts
T1110 - Brute Force
T1213 - Data from Information Repositories
  • 30 Rules
  • 17 Models
Palo Alto NGFWT1078 - Valid Accounts
T1083 - File and Directory Discovery
T1110 - Brute Force
  • 44 Rules
  • 25 Models
Traps Endpoint Security ManagerT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Password Manager Pro

ProductMITRE ATT&CK® TTPContent
Password Manager ProT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Ping Identity

ProductMITRE ATT&CK® TTPContent
Ping IdentityT1078 - Valid Accounts
  • 20 Rules
  • 11 Models
PingOneT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: PostgreSQL

ProductMITRE ATT&CK® TTPContent
PostgreSQLT1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models

Vendor: Proofpoint

ProductMITRE ATT&CK® TTPContent
ObserveITT1003 - OS Credential Dumping
  • 1 Rules
Proofpoint Email ProtectionT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Proofpoint Enterprise ProtectionT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Quest Software

ProductMITRE ATT&CK® TTPContent
Quest Change Auditor for Active DirectoryT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: RSA

ProductMITRE ATT&CK® TTPContent
RSA Authentication ManagerT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
SecurIDT1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: RangerAudit

ProductMITRE ATT&CK® TTPContent
RangerAuditT1078 - Valid Accounts
  • 1 Rules

Vendor: Riverbed Steelhead

ProductMITRE ATT&CK® TTPContent
Riverbed SteelheadT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Rubrik

ProductMITRE ATT&CK® TTPContent
Rubrik Cloud Data ManagementT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: SAP

ProductMITRE ATT&CK® TTPContent
SAPT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 30 Rules
  • 17 Models
SuccessFactorsT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Safenet

ProductMITRE ATT&CK® TTPContent
ThalesT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Sailpoint

ProductMITRE ATT&CK® TTPContent
IdentityNowT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: Salesforce

ProductMITRE ATT&CK® TTPContent
SalesforceT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: Secomea

ProductMITRE ATT&CK® TTPContent
SecomeaT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: SecureAuth

ProductMITRE ATT&CK® TTPContent
SecureAuth IDPT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
SecureAuth LoginT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
ProductMITRE ATT&CK® TTPContent
SecureLinkT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: SecureNet

ProductMITRE ATT&CK® TTPContent
SecureNetT1110 - Brute Force
  • 1 Rules
  • 1 Models

Vendor: Semperis

ProductMITRE ATT&CK® TTPContent
Semperis DSPT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: SentinelOne

ProductMITRE ATT&CK® TTPContent
Event Viewer - SentineloneT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Singularity PlatformT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models
VigilanceT1078 - Valid Accounts
  • 20 Rules
  • 11 Models

Vendor: ServiceNow

ProductMITRE ATT&CK® TTPContent
ServiceNowT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: Shibboleth

ProductMITRE ATT&CK® TTPContent
ShibbolethT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Silverfort

ProductMITRE ATT&CK® TTPContent
Silverfort Authentication PlatformT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: SiteMinder

ProductMITRE ATT&CK® TTPContent
Symantec SiteMinderT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: SkySea

ProductMITRE ATT&CK® TTPContent
SkySea ClientViewT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models

Vendor: Skyformation

ProductMITRE ATT&CK® TTPContent
SkyformationT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Snowflake

ProductMITRE ATT&CK® TTPContent
SnowflakeT1213 - Data from Information Repositories
  • 18 Rules
  • 10 Models

Vendor: Sophos

ProductMITRE ATT&CK® TTPContent
Sophos Endpoint ProtectionT1083 - File and Directory Discovery
  • 24 Rules
  • 13 Models
Sophos XG FirewallT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: SunOne

ProductMITRE ATT&CK® TTPContent
SunOneT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: Swift

ProductMITRE ATT&CK® TTPContent
SwiftT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Swivel

ProductMITRE ATT&CK® TTPContent
SwivelT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Sybase

ProductMITRE ATT&CK® TTPContent
SybaseT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 15 Rules
  • 9 Models

Vendor: Symantec

ProductMITRE ATT&CK® TTPContent
Symantec Advanced Threat ProtectionT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models
Symantec DLPT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Symantec Endpoint ProtectionT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 29 Rules
  • 17 Models

Vendor: Tanium

ProductMITRE ATT&CK® TTPContent
Tanium Cloud PlatformT1078 - Valid Accounts
  • 20 Rules
  • 11 Models
Tanium Core PlatformT1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 6 Rules
  • 4 Models
Tanium Integrity MonitorT1003 - OS Credential Dumping
T1083 - File and Directory Discovery
  • 25 Rules
  • 13 Models

Vendor: Teradata

ProductMITRE ATT&CK® TTPContent
Teradata RDBMST1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models

Vendor: Trend Micro

ProductMITRE ATT&CK® TTPContent
Deep Discovery InspectorT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Trend Micro ScanMailT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Tufin

ProductMITRE ATT&CK® TTPContent
Tufin SecureTrackT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Tyco

ProductMITRE ATT&CK® TTPContent
CCURE Building Management SystemT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Unix

ProductMITRE ATT&CK® TTPContent
AuditbeatT1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 6 Rules
  • 4 Models
UnixT1003 - OS Credential Dumping
T1078 - Valid Accounts
T1083 - File and Directory Discovery
T1213 - Data from Information Repositories
  • 40 Rules
  • 22 Models
Unix AuditdT1003 - OS Credential Dumping
T1078 - Valid Accounts
  • 6 Rules
  • 4 Models
Unix NamedT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Unix dhcpdT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
rsyslogT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: VMware

ProductMITRE ATT&CK® TTPContent
Carbon Black App ControlT1003 - OS Credential Dumping
  • 1 Rules
Carbon Black CEST1003 - OS Credential Dumping
T1083 - File and Directory Discovery
  • 25 Rules
  • 13 Models
Carbon Black EDRT1003 - OS Credential Dumping
T1213 - Data from Information Repositories
  • 11 Rules
  • 5 Models
VMware AirWatchT1078 - Valid Accounts
  • 19 Rules
  • 11 Models
VMware ESXiT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 15 Rules
  • 9 Models
VMware ViewT1078 - Valid Accounts
  • 5 Rules
  • 4 Models
vCenterT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Vectra

ProductMITRE ATT&CK® TTPContent
Vectra Cognito StreamT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 29 Rules
  • 17 Models

Vendor: ViaScope

ProductMITRE ATT&CK® TTPContent
ViaScope IPScanT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Wiz

ProductMITRE ATT&CK® TTPContent
WizT1078 - Valid Accounts
T1213 - Data from Information Repositories
  • 15 Rules
  • 9 Models

Vendor: Workday

ProductMITRE ATT&CK® TTPContent
WorkdayT1078 - Valid Accounts
  • 5 Rules
  • 4 Models

Vendor: Xceedium

ProductMITRE ATT&CK® TTPContent
XceediumT1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Xiting

ProductMITRE ATT&CK® TTPContent
XAMST1078 - Valid Accounts
  • 6 Rules
  • 4 Models

Vendor: Zeek

ProductMITRE ATT&CK® TTPContent
ZeekT1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 43 Rules
  • 24 Models

Vendor: Zendesk

ProductMITRE ATT&CK® TTPContent
ZendeskT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor:

Vendor: iManage

ProductMITRE ATT&CK® TTPContent
iManageT1078 - Valid Accounts
  • 19 Rules
  • 11 Models

Vendor: jSONAR

ProductMITRE ATT&CK® TTPContent
SonarGT1213 - Data from Information Repositories
  • 10 Rules
  • 5 Models

Vendor: oVirt

ProductMITRE ATT&CK® TTPContent
oVirtT1078 - Valid Accounts
  • 19 Rules
  • 11 Models