Vendor: Cisco Product: Duo Access Security Rules Models MITRE TTPs Event Types Parsers 168 83 25 7 7 Use-Case Event Types/Parsers MITRE TTP Content Abnormal Authentication & Access app-login ↳q-duo-failed-app-login ↳duo-failed-app-login ↳s-duo-failed-app-login-1 ↳s-duo-failed-app-login ↳cef-duo-failed-app-login-1 ↳cef-duo-app-activity authentication-failed ↳q-duo-auth-successful ↳cef-duo-authentication ↳s-duo-app-activity ↳q-duo-app-activity-4 ↳q-duo-app-activity-3 ↳q-duo-app-activity-5 ↳duo-app-activity ↳q-duo-app-activity-2 ↳q-duo-app-activity-1 ↳cef-duo-app-activity authentication-successful ↳s-duo-auth-successful ↳s-duo-auth-set-ip ↳json-duo-auth-attempt ↳u-duo-auth-json ↳cef-duo-auth ↳s-duo-auth-json ↳s-duo-auth-json-1 ↳json-duo-auth-attempt ↳u-duo-auth-json ↳cef-duo-auth ↳s-duo-auth-json ↳s-duo-auth-json-1 ↳q-duo-auth-failed ↳cef-duo-authentication failed-logon ↳cef-duo-VPN-login file-delete ↳cef-duo-app-activity vpn-login ↳cef-duo-VPN-login-failed vpn-logout ↳q-duo-app-login ↳duo-app-login ↳cef-duo-app-login ↳s-duo-app-login ↳cef-duo-app-login-1 ↳cef-duo-app-activity T1021 - Remote ServicesT1078 - Valid AccountsT1110 - Brute ForceT1133 - External Remote Services 74 Rules36 Models Account Manipulation app-login ↳q-duo-failed-app-login ↳duo-failed-app-login ↳s-duo-failed-app-login-1 ↳s-duo-failed-app-login ↳cef-duo-failed-app-login-1 ↳cef-duo-app-activity authentication-failed ↳q-duo-auth-successful ↳cef-duo-authentication ↳s-duo-app-activity ↳q-duo-app-activity-4 ↳q-duo-app-activity-3 ↳q-duo-app-activity-5 ↳duo-app-activity ↳q-duo-app-activity-2 ↳q-duo-app-activity-1 ↳cef-duo-app-activity authentication-successful ↳s-duo-auth-successful ↳s-duo-auth-set-ip ↳json-duo-auth-attempt ↳u-duo-auth-json ↳cef-duo-auth ↳s-duo-auth-json ↳s-duo-auth-json-1 ↳json-duo-auth-attempt ↳u-duo-auth-json ↳cef-duo-auth ↳s-duo-auth-json ↳s-duo-auth-json-1 ↳q-duo-auth-failed ↳cef-duo-authentication failed-logon ↳cef-duo-VPN-login file-delete ↳cef-duo-app-activity vpn-login ↳cef-duo-VPN-login-failed vpn-logout ↳q-duo-app-login ↳duo-app-login ↳cef-duo-app-login ↳s-duo-app-login ↳cef-duo-app-login-1 ↳cef-duo-app-activity T1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate Permissions 7 Rules7 Models Next Page -->> ATT&CK Matrix for Enterprise Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact External Remote ServicesValid AccountsPhishing User Execution External Remote ServicesValid AccountsAccount ManipulationAccount Manipulation: Exchange Email Delegate Permissions Valid AccountsExploitation for Privilege Escalation Indicator Removal on Host: File DeletionValid AccountsUse Alternate Authentication MaterialUse Alternate Authentication Material: Pass the HashIndicator Removal on HostUse Alternate Authentication Material: Web Session CookieUse Alternate Authentication Material: Pass the Ticket OS Credential DumpingBrute ForceSteal or Forge Kerberos TicketsSteal or Forge Kerberos Tickets: Kerberoasting File and Directory Discovery Exploitation of Remote ServicesRemote ServicesUse Alternate Authentication Material Proxy: Multi-hop ProxyApplication Layer ProtocolProxy Exfiltration Over Alternative ProtocolExfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolExfiltration Over Physical Medium: Exfiltration over USBData Transfer Size LimitsExfiltration Over Physical MediumAutomated Exfiltration