Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ASUPIM |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Load Balancer |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
AirWatch |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
AWS Bastion |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
AppSense Application Manager |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Armis |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BOTsink |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Auth0 |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Barracuda Firewall |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BeyondTrust PowerBroker |
|
T1078 - Valid Accounts |
|
BeyondTrust Privileged Identity |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BlackBerry Protect |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BlueCat Networks DHCP |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
CA Privileged Access Manager Server Control |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
CDS |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Cato Cloud |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Centrify Authentication Service |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Centrify Infrastructure Services |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Check Point NGFW |
|
T1003 - OS Credential Dumping |
|
Check Point Security Gateway |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Cisco ACS |
|
T1078 - Valid Accounts |
|
Cisco Adaptive Security Appliance |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts |
|
Cisco ISE |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts |
|
Cisco Meraki MX appliances |
|
T1003 - OS Credential Dumping |
|
Cisco Secure Network Analytics |
|
T1003 - OS Credential Dumping |
|
Cisco TACACS |
|
T1078 - Valid Accounts |
|
Duo Access Security |
|
T1003 - OS Credential Dumping T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Citrix Endpoint Management |
|
T1078 - Valid Accounts |
|
Citrix Netscaler |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Cognitas CrossLink |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Falcon |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
CyberArk Vault |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation T1110 - Brute Force |
|
Privileged Threat Analytics |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
One Identity Manager |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Digital Guardian Endpoint Protection |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
DTEX InTERCEPT |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ESET Endpoint Security |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Egnyte |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
EnSilo |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Zebra wireless LAN management |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BIG-IP DNS |
|
T1003 - OS Credential Dumping |
|
F5 BIG-IP |
|
T1078 - Valid Accounts |
|
F5 BIG-IP Access Policy Manager (APM) |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Fidelis Network |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
FortiAuthenticator |
|
T1003 - OS Credential Dumping |
|
Fortinet VPN |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
GTBInspector |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
GoAnywhere MFT |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Aruba Mobility Master |
|
T1078 - Valid Accounts |
|
HP Comware |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Powertech Identity Access Manager (BoKs) |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Honeywell Pro-Watch |
|
T1110 - Brute Force |
|
honeywell siama |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
IBM DB2 |
|
T1078 - Valid Accounts |
|
IBM Sterling B2B Integrator |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Illumio |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
MoveIt DMZ |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Juniper Networks |
|
T1110 - Brute Force |
|
Juniper Networks Pulse Secure |
|
T1003 - OS Credential Dumping |
|
Juniper VPN |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Kemp LoadMaster |
|
T1078 - Valid Accounts |
|
Load Balancer |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
LanScope Cat |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SSH |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
MasterSAM PAM |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
McAfee Endpoint Security |
|
T1078 - Valid Accounts |
|
McAfee IDPS |
|
T1003 - OS Credential Dumping |
|
McAfee Solidifier |
|
T1078 - Valid Accounts |
|
Skyhigh Networks CASB |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Microsoft Azure |
|
T1110 - Brute Force |
|
Microsoft Azure AD Identity Protection |
|
T1078 - Valid Accounts |
|
Microsoft Defender ATP |
|
T1078 - Valid Accounts |
|
Microsoft Office 365 |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Microsoft Windows |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation T1110 - Brute Force |
|
Web Application Proxy |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
NCP |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Namespace rDirectory |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Netwrix Auditor |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
OSSEC |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ObserveIT |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Okta Adaptive MFA |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Onapsis |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Oracle DB |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
GlobalProtect |
|
T1078 - Valid Accounts |
|
Magnifier |
|
T1078 - Valid Accounts |
|
NGFW |
|
T1078 - Valid Accounts |
|
Traps |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Password Manager Pro |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ObserveIT |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Change Auditor |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SAP |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SSL Open VPN |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
FAM |
|
T1078 - Valid Accounts |
|
IdentityNow |
|
T1003 - OS Credential Dumping |
|
SecurityIQ |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Secure Computing SafeWord |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ServiceNow |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Sonicwall |
|
T1003 - OS Credential Dumping T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Swipes |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Swivel |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Symantec Critical System Protection |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation T1110 - Brute Force |
|
Symantec DLP |
|
T1110 - Brute Force |
|
Symantec EDR |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Symantec Endpoint Protection |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Thycotic Secret Server |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
TrapX |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Unix |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Unix Auditd |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
VMWare ID Manager (VIDM) |
|
T1078 - Valid Accounts |
|
VMware Carbon Black App Control |
|
T1078 - Valid Accounts |
|
VMware ESXi |
|
T1078 - Valid Accounts |
|
VMware VCenter |
|
T1078 - Valid Accounts |
|
VMware View |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Vormetric |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1098 - Account Manipulation |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Zeek Network Security Monitor |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SonarG |
|
T1078 - Valid Accounts |
|