Skip to content

Latest commit

 

History

History
13 lines (11 loc) · 1.71 KB

r_m_imperva_incapsula_Ransomware.md

File metadata and controls

13 lines (11 loc) · 1.71 KB

Vendor: Imperva

Product: Incapsula

Use-Case: Ransomware

Rules Models MITRE TTPs Event Types Parsers
3 0 3 2 2
Event Type Rules Models
authentication-failed T1078 - Valid Accounts
Auth-Ransomware-Shost-Failed: User authentication or login failure from a known ransomware IP
web-activity-allowed T1071.001 - Application Layer Protocol: Web Protocols
WEB-UI-Ransomware: User attempted to connect to IP address which is associated to Ransomware

T1071 - Application Layer Protocol
A-WEB-DynamicDNS: Asset attempted access to a domain generated using Dynamic DNS service