Use-Case Activity Type (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content Compromised Credentials vpn-login:fail (failed-vpn-login) ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform endpoint-login:success (remote-logon) ↳f5-bigip-kv-ssh-traffic-success-sshd vpn-login:success (vpn-login) ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform ↳f5-bigip-kv-vpn-login-success-started vpn-logout:success (vpn-logout) ↳f5-bigip-kv-vpn-logout-success-closed ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform T1021 - Remote ServicesT1078 - Valid AccountsT1078.002 - T1078.002T1078.003 - Valid Accounts: Local AccountsT1110 - Brute ForceT1133 - External Remote ServicesT1550 - Use Alternate Authentication MaterialT1550.003 - Use Alternate Authentication Material: Pass the TicketT1558 - Steal or Forge Kerberos Tickets 58 Rules27 Models Lateral Movement endpoint-login:fail (authentication-failed) ↳f5-bigip-kv-endpoint-login-fail-accessdenied vpn-login:fail (failed-vpn-login) ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform network-traffic:fail (network-connection-failed) ↳f5-bigip-str-network-traffic-fail-855 ↳f5-bigip-str-network-traffic-fail-connectionerror endpoint-login:success (remote-logon) ↳f5-bigip-kv-ssh-traffic-success-sshd vpn-login:success (vpn-login) ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform ↳f5-bigip-kv-vpn-login-success-started vpn-logout:success (vpn-logout) ↳f5-bigip-kv-vpn-logout-success-closed ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform T1018 - Remote System DiscoveryT1021 - Remote ServicesT1078 - Valid AccountsT1090 - ProxyT1090.003 - Proxy: Multi-hop ProxyT1190 - Exploit Public Fasing ApplicationT1550 - Use Alternate Authentication MaterialT1550.002 - Use Alternate Authentication Material: Pass the HashT1550.003 - Use Alternate Authentication Material: Pass the TicketT1558 - Steal or Forge Kerberos TicketsT1558.003 - Steal or Forge Kerberos Tickets: KerberoastingTA0010 - TA0010TA0011 - TA0011 53 Rules22 Models Malware network-traffic:fail (network-connection-failed) ↳f5-bigip-str-network-traffic-fail-855 ↳f5-bigip-str-network-traffic-fail-connectionerror endpoint-login:success (remote-logon) ↳f5-bigip-kv-ssh-traffic-success-sshd vpn-login:success (vpn-login) ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform ↳f5-bigip-kv-vpn-login-success-started T1078 - Valid AccountsT1550 - Use Alternate Authentication MaterialT1550.003 - Use Alternate Authentication Material: Pass the TicketT1558 - Steal or Forge Kerberos TicketsTA0002 - TA0002TA0011 - TA0011 8 Rules2 Models Privilege Abuse endpoint-login:success (remote-logon) ↳f5-bigip-kv-ssh-traffic-success-sshd vpn-login:success (vpn-login) ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform ↳f5-bigip-kv-vpn-login-success-started vpn-logout:success (vpn-logout) ↳f5-bigip-kv-vpn-logout-success-closed ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform T1078 - Valid AccountsT1078.002 - T1078.002T1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate PermissionsT1133 - External Remote Services 12 Rules8 Models Privilege Escalation endpoint-login:success (remote-logon) ↳f5-bigip-kv-ssh-traffic-success-sshd vpn-logout:success (vpn-logout) ↳f5-bigip-kv-vpn-logout-success-closed ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform T1078 - Valid AccountsT1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate PermissionsT1555 - Credentials from Password StoresT1555.005 - T1555.005 7 Rules6 Models Ransomware endpoint-login:fail (authentication-failed) ↳f5-bigip-kv-endpoint-login-fail-accessdenied vpn-login:fail (failed-vpn-login) ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform endpoint-login:success (remote-logon) ↳f5-bigip-kv-ssh-traffic-success-sshd vpn-login:success (vpn-login) ↳f5-bigip-str-vpn-success-sessionsslcert ↳f5-bigip-str-vpn-login-success-hostname ↳f5-bigip-str-vpn-login-success-platform ↳f5-bigip-kv-vpn-login-success-started T1078 - Valid Accounts 1 Rules