Product | Event Types | MITRE TTP | Content |
---|---|---|---|
APC |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Abnormal Security |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Kiteworks |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Airlock |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Cloud Akamai |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Alert Logic |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
AWS Bastion |
|
T1078 - Valid Accounts |
|
AWS CloudTrail |
|
T1078 - Valid Accounts |
|
AWS GuardDuty |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Anywhere365 |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Apache Guacamole |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Apache Subversion |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
AssetView |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BOTsink |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Auth0 |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Barracuda Firewall |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BeyondTrust Privilege Management |
|
T1003 - OS Credential Dumping |
|
BeyondTrust Privileged Identity |
|
T1078 - Valid Accounts |
|
BeyondTrust Secure Remote Access |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Bitdefender GravityZone |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Bitglass CASB |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BlackBerry Protect |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Box Cloud Content Management |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Bromium Advanced Endpoint Security |
|
T1083 - File and Directory Discovery |
|
Bromium Secure Platform |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
CA Privileged Access Manager Server Control |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Centrify Audit and Monitoring Service |
|
T1083 - File and Directory Discovery |
|
Centrify Authentication Service |
|
T1003 - OS Credential Dumping |
|
Centrify Zero Trust Privilege Services |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Check Point NGFW |
|
T1083 - File and Directory Discovery T1110 - Brute Force |
|
Check Point Security Gateway |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Cimtrak |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ACI |
|
T1078 - Valid Accounts |
|
AnyConnect |
|
T1003 - OS Credential Dumping |
|
Cisco ACS |
|
T1078 - Valid Accounts |
|
Cisco Adaptive Security Appliance |
|
T1003 - OS Credential Dumping T1110 - Brute Force |
|
Cisco Call Manager |
|
T1078 - Valid Accounts |
|
Cisco Console |
|
T1078 - Valid Accounts |
|
Cisco Firepower |
|
T1078 - Valid Accounts |
|
Cisco ISE |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Cisco Meraki MX appliances |
|
T1110 - Brute Force |
|
Cisco NPE |
|
T1003 - OS Credential Dumping |
|
Cisco Secure Network Analytics |
|
T1110 - Brute Force |
|
Duo Access Security |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery T1110 - Brute Force |
|
Proxy Umbrella |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Citrix AppFW |
|
T1213 - Data from Information Repositories |
|
Citrix Netscaler |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Citrix Netscaler VPN |
|
T1078 - Valid Accounts |
|
Citrix ShareFile |
|
T1078 - Valid Accounts |
|
Citrix XenApp |
|
T1078 - Valid Accounts |
|
Citrix XenDesktop |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Clearsense |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Cloud Application |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Cloudflare CDN |
|
T1078 - Valid Accounts |
|
Cloudflare Insights |
|
T1078 - Valid Accounts |
|
Cloudflare WAF |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Code42 Incydr |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Contrast Security |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Falcon |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
CyberArk Endpoint Privilege Management |
|
T1083 - File and Directory Discovery |
|
CyberArk Vault |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Privileged Session Manager |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Darktrace |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Dell EMC Isilon |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
RSA Authentication Manager |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Digital Guardian Endpoint Protection |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Dropbox |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
DTEX InTERCEPT |
|
T1003 - OS Credential Dumping T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
EMP |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ESET Endpoint Security |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ESector DEFESA |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Egnyte |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Epic SIEM |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Exabeam Advanced Analytics |
|
T1078 - Valid Accounts |
|
Exabeam DL |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
F-Secure Client Security |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
BIG-IP DNS |
|
T1110 - Brute Force |
|
F5 Advanced Web Application Firewall (WAF) |
|
T1003 - OS Credential Dumping |
|
F5 BIG-IP |
|
T1078 - Valid Accounts |
|
F5 BIG-IP Access Policy Manager (APM) |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
F5 BIG-IP Advanced Firewall Module (AFM) |
|
T1078 - Valid Accounts |
|
F5 BIG-IP Application Security Manager (ASM) |
|
T1078 - Valid Accounts |
|
WebSafe |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
FTP |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
FileAuditor |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
FireEye Endpoint Security (HX) |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Forcepoint CASB |
|
T1078 - Valid Accounts |
|
Forcepoint NGFW |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Forescout CounterACT |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
FortiAuthenticator |
|
T1110 - Brute Force |
|
Fortinet Enterprise Firewall |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Fortinet UTM |
|
T1078 - Valid Accounts |
|
Fortinet VPN |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
GitHub |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
GoAnywhere MFT |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
|
T1078 - Valid Accounts |
|
|
Google Calendar |
|
T1078 - Valid Accounts |
|
Google Drive |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Aruba Wireless controller |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Powertech Identity Access Manager (BoKs) |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Enterprise Network Firewall |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
IBM DB2 |
|
T1083 - File and Directory Discovery |
|
IBM Racf |
|
T1078 - Valid Accounts |
|
IBM Sametime |
|
T1078 - Valid Accounts |
|
IBM Sterling B2B Integrator |
|
T1078 - Valid Accounts |
|
Infosphere Guardium |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
IXIA ThreatArmor |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
CounterBreach |
|
T1213 - Data from Information Repositories |
|
Imperva File Activity Monitoring (FAM) |
|
T1083 - File and Directory Discovery |
|
Imperva SecureSphere |
|
T1078 - Valid Accounts T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Imprivata |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
InfoWatch |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Infoblox |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
IPswitch MoveIt |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
MoveIt DMZ |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Juniper Networks Pulse Secure |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Juniper VPN |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
KABA EXOS |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Kaspersky AV |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Kemp LoadMaster |
|
T1078 - Valid Accounts |
|
Load Balancer |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
LEAP |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SharePoint |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
LanScope Cat |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
LastPass |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Linux DHCP |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
RemotelyAnywhere |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Lyrix |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
MariaDB |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
MDAM |
|
T1213 - Data from Information Repositories |
|
McAfee Endpoint Security |
|
T1083 - File and Directory Discovery |
|
McAfee IDPS |
|
T1110 - Brute Force |
|
McAfee NSM |
|
T1078 - Valid Accounts |
|
Mcafee EPO |
|
T1078 - Valid Accounts |
|
Skyhigh Networks CASB |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Advanced Threat Analytics (ATA) |
|
T1003 - OS Credential Dumping |
|
Exchange |
|
T1078 - Valid Accounts |
|
Microsoft Azure |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery T1213 - Data from Information Repositories |
|
Microsoft Azure Active Directory |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts |
|
Microsoft Cloud App Security (MCAS) |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Microsoft Defender ATP |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Microsoft Office 365 |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Microsoft OneDrive |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Microsoft SQL Server |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery T1213 - Data from Information Repositories |
|
Microsoft Sysmon |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Microsoft Windows |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery T1110 - Brute Force T1213 - Data from Information Repositories |
|
Windows Defender |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Mimecast |
|
T1078 - Valid Accounts |
|
Mimecast Email Security |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Morphisec EPTP |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Mysql |
|
T1078 - Valid Accounts T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
NCP |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Namespace rDirectory |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Nasuni |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
NetApp |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
NetDocs |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
NetIQ |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Netskope Security Cloud |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Netwrix Auditor |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Nokia VitalQIP |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
eDirectory |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
OSSEC |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ObserveIT |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Okta Adaptive MFA |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Onapsis |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
OneLogin |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Digipass |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Oracle AVDF |
|
T1078 - Valid Accounts T1213 - Data from Information Repositories |
|
Oracle Access Manager |
|
T1078 - Valid Accounts |
|
Oracle DB |
|
T1213 - Data from Information Repositories |
|
Oracle Solaris |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Ordr SCE |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Osirium |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Cortex XDR |
|
T1078 - Valid Accounts |
|
NGFW |
|
T1078 - Valid Accounts |
|
Palo Alto Aperture |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Password Manager Pro |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Ping Identity |
|
T1078 - Valid Accounts |
|
PingOne |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
PostScript |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
PostgreSQL |
|
T1083 - File and Directory Discovery T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
PowerSentry |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Prisma Cloud |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ObserveIT |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ProxySG |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Change Auditor |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
RS2 |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
RSA |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
RUID |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
RangerAudit |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
InsightVM |
|
T1003 - OS Credential Dumping |
|
Nexpose |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SAP |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SFTP |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SSL Open VPN |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
FAM |
|
T1083 - File and Directory Discovery |
|
IdentityNow |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
SecurityIQ |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Salesforce |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SecureLink |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SecureNet |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SentinelOne |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ServiceNow |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Shibboleth SSO |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Silverfort |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
ClientView |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Slack |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Snort |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Snowflake |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Sonicwall |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Sophos Endpoint Protection |
|
T1078 - Valid Accounts |
|
Sophos SafeGuard |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
StealthIntercept |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Suricata |
|
T1078 - Valid Accounts |
|
Suricata IDS |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Swift |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Swipes |
|
T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Swivel |
|
T1078 - Valid Accounts T1110 - Brute Force |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Sybase |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Symantec Advanced Threat Protection |
|
T1078 - Valid Accounts |
|
Symantec Blue Coat Content Analysis System |
|
T1078 - Valid Accounts |
|
Symantec CloudSOC |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Symantec EDR |
|
T1083 - File and Directory Discovery |
|
Symantec Email Security.cloud |
|
T1078 - Valid Accounts |
|
Symantec Endpoint Protection Mobile |
|
T1078 - Valid Accounts |
|
Symantec VIP |
|
T1078 - Valid Accounts |
|
Symantec WSS |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Endpoint Platform |
|
T1003 - OS Credential Dumping T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Teradata RDBMS |
|
T1213 - Data from Information Repositories |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Thycotic Secret Server |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
TitanFTP |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Apex One |
|
T1078 - Valid Accounts |
|
Deep Discovery Inspector |
|
T1078 - Valid Accounts |
|
TippingPoint NGIPS |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Tripwire Enterprise |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
SecureTrack |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
CCURE Building Management System |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Auditbeat |
|
T1078 - Valid Accounts |
|
Unix |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery T1213 - Data from Information Repositories |
|
Unix Auditd |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1213 - Data from Information Repositories |
|
Unix dhcpd |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Carbon Black |
|
T1003 - OS Credential Dumping |
|
Carbon Black EDR |
|
T1003 - OS Credential Dumping T1083 - File and Directory Discovery |
|
VMWare ID Manager (VIDM) |
|
T1078 - Valid Accounts |
|
VMware Carbon Black App Control |
|
T1003 - OS Credential Dumping T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
VMware Carbon Black Cloud Endpoint Standard |
|
T1003 - OS Credential Dumping T1083 - File and Directory Discovery |
|
VMware Carbon Black EDR |
|
T1078 - Valid Accounts |
|
VMware View |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Data Security Platform |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Vormetric |
|
T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Workday |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
XPS |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Xceedium |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Xerox |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Zeek Network Security Monitor |
|
T1078 - Valid Accounts T1083 - File and Directory Discovery |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Zlock |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
Zscaler Private Access |
|
T1003 - OS Credential Dumping |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
iManage |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
oVirt |
|
T1078 - Valid Accounts |
|
Product | Event Types | MITRE TTP | Content |
---|---|---|---|
pfSense |
|
T1083 - File and Directory Discovery |
|