Skip to content

Latest commit

 

History

History
12 lines (10 loc) · 896 Bytes

r_m_sentinelone_vigilance_Privilege_Escalation.md

File metadata and controls

12 lines (10 loc) · 896 Bytes

Vendor: SentinelOne

Product: Vigilance

Rules Models MITRE ATT&CK® TTPs Event Types Parsers
3 1 1 1 1
Event Type Rules Models
app-activity T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
EM-InB-Ex: A user has been given mailbox permissions for an executive user
EM-InB-Perm-N-F: First time a user has given mailbox permissions on another mailbox that is not their own
EM-InB-Perm-N-A: Abnormal for user to give mailbox permissions
EM-InB-Perm-N: Models users who give mailbox permissions