Skip to content

Latest commit

 

History

History
20 lines (18 loc) · 17.1 KB

uc_cloud_data_protection.md

File metadata and controls

20 lines (18 loc) · 17.1 KB

Use Case: Cloud Data Protection

Vendor: Amazon

Product Event Types MITRE ATT&CK® TTP Content
AWS CloudTrail
  • app-activity
  • app-activity-failed
  • app-login
  • aws-bucket-cors
  • aws-bucket-cors-failed
  • aws-bucket-create
  • aws-bucket-create-failed
  • aws-bucket-policy
  • aws-bucket-policy-failed
  • aws-bucket-putaccessblock
  • aws-bucket-putaccessblock-failed
  • aws-compute-list
  • aws-compute-list-failed
  • aws-function-write
  • aws-function-write-failed
  • aws-general-activity
  • aws-general-activity-failed
  • aws-identity-addtogroup
  • aws-identity-addtogroup-failed
  • aws-identity-creds-write
  • aws-identity-creds-write-failed
  • aws-identity-list
  • aws-identity-list-failed
  • aws-identity-loginprofile
  • aws-identity-loginprofile-failed
  • aws-identity-write
  • aws-identity-write-failed
  • aws-image-create
  • aws-image-create-failed
  • aws-image-modify
  • aws-image-modify-failed
  • aws-instance-command
  • aws-instance-command-failed
  • aws-instance-create
  • aws-instance-create-failed
  • aws-instance-creds-read
  • aws-instance-creds-read-failed
  • aws-instance-creds-write
  • aws-instance-creds-write-failed
  • aws-instance-login
  • aws-instance-login-failed
  • aws-instance-modify
  • aws-instance-modify-failed
  • aws-instance-screenshot
  • aws-instance-screenshot-failed
  • aws-key-policy
  • aws-key-policy-failed
  • aws-login
  • aws-login-failed
  • aws-policy-attach
  • aws-policy-attach-failed
  • aws-policy-list
  • aws-policy-list-failed
  • aws-policy-setversion
  • aws-policy-setversion-failed
  • aws-policy-write
  • aws-policy-write-failed
  • aws-role-assume
  • aws-role-assume-failed
  • aws-role-assumepolicy
  • aws-role-assumepolicy-failed
  • aws-role-switch
  • aws-role-switch-failed
  • aws-role-write
  • aws-role-write-failed
  • aws-snapshot-create
  • aws-snapshot-create-failed
  • aws-snapshot-modify
  • aws-snapshot-modify-failed
  • aws-storage-acl
  • aws-storage-acl-failed
  • aws-storage-list
  • aws-storage-list-failed
  • aws-storageobject-copy
  • aws-storageobject-copy-failed
  • aws-storageobject-read
  • aws-storageobject-read-failed
  • aws-storageobject-write
  • aws-storageobject-write-failed
  • aws-volume-attach
  • aws-volume-attach-failed
  • aws-volume-create
  • aws-volume-create-failed
  • aws-volume-modify
  • aws-volume-modify-failed
  • cloud-admin-activity
  • cloud-admin-activity-failed
  • failed-app-login
  • storage-access
  • storage-activity
  • storage-activity-failed
T1074 - Data Staged
T1113 - Screen Capture
T1530 - Data from Cloud Storage Object
T1580 - T1580
TA0001 - TA0001
TA0004 - TA0004
TA0007 - TA0007
TA0009 - TA0009
  • 30 Rules
  • 21 Models

Vendor: Google

Product Event Types MITRE ATT&CK® TTP Content
Cloud Platform
  • app-activity
  • cloud-admin-activity
  • cloud-admin-activity-failed
  • gcp-disk-attach
  • gcp-disk-create
  • gcp-image-create
  • gcp-instance-create
  • gcp-instance-setmachinetype
  • gcp-instance-setmetadata
  • gcp-policy-write
  • gcp-role-write
  • gcp-serviceaccount-creds-write
  • gcp-serviceaccount-write
  • gcp-snapshot-create
  • gcp-storageobject-acl
  • netflow-connection
  • network-alert
  • storage-access
  • storage-activity
  • storage-activity-failed
  • web-activity-allowed
  • web-activity-denied
T1530 - Data from Cloud Storage Object
TA0004 - TA0004
TA0009 - TA0009
  • 8 Rules
  • 7 Models

Vendor: Microsoft

Product Event Types MITRE ATT&CK® TTP Content
Microsoft Azure
  • azure-blob-read
  • azure-blob-write
  • azure-container-acl
  • azure-disk-write
  • azure-image-write
  • azure-instance-creds-write
  • azure-instance-write
  • azure-keyvault-read
  • azure-keyvault-write
  • azure-metrics
  • azure-role-assign
  • azure-role-write
  • azure-snapshot-write
  • azure-storage-list
T1078.004 - Valid Accounts: Cloud Accounts
T1204 - User Execution
T1580 - T1580
TA0009 - TA0009
  • 5 Rules
  • 5 Models

Vendor: SAP

Product Event Types MITRE ATT&CK® TTP Content
SAP
  • account-creation
  • account-deleted
  • account-lockout
  • account-password-change
  • account-unlocked
  • app-activity
  • app-login
  • authentication-failed
  • authentication-successful
  • failed-app-login
  • file-download
  • file-write
  • gcp-bucket-create
  • gcp-compute-list
  • gcp-function-write
  • gcp-general-activity
  • gcp-instance-screenshot
  • gcp-role-list
  • gcp-serviceaccount-creds-write
  • gcp-storage-list
  • gcp-storageobject-read
  • gcp-storageobject-write
  • remote-logon
T1074 - Data Staged
T1113 - Screen Capture
T1580 - T1580
  • 4 Rules
  • 4 Models