Skip to content

Latest commit

 

History

History
19 lines (17 loc) · 6.88 KB

ds_honeywell_honeywell_pro-watch.md

File metadata and controls

19 lines (17 loc) · 6.88 KB

Vendor: Honeywell

Product: Honeywell Pro-Watch

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
12 6 1 1 8
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Abnormal Authentication & Access physical_location-access:fail (failed-physical-access)
honeywell-pw-json-physical-location-access-areaname
honeywell-pw-xml-physical-location-access-evntdat
honeywell-pw-kv-physical-location-access-success-refidtyp
honeywell-pw-kv-physical-location-access-success-cardno
honeywell-pw-cef-physical-location-access-success-location
honeywell-pw-kv-physical-location-access-success-location
honeywell-pw-json-physical-location-access-success-badgeno
honeywell-pw-csv-physical-location-access-success-exabeam
honeywell-pw-kv-physical-location-access-success-accessgranted

physical_location-access:success (physical-access)
honeywell-pw-json-physical-location-access-areaname
honeywell-pw-xml-physical-location-access-evntdat
honeywell-pw-kv-physical-location-access-success-refidtyp
honeywell-pw-kv-physical-location-access-success-cardno
honeywell-pw-cef-physical-location-access-success-location
honeywell-pw-kv-physical-location-access-success-location
honeywell-pw-json-physical-location-access-success-badgeno
honeywell-pw-csv-physical-location-access-success-exabeam
honeywell-pw-kv-physical-location-access-success-accessgranted
T1078 - Valid Accounts
  • 3 Rules
  • 2 Models
Physical Security physical_location-access:fail (failed-physical-access)
honeywell-pw-json-physical-location-access-areaname
honeywell-pw-xml-physical-location-access-evntdat
honeywell-pw-kv-physical-location-access-success-refidtyp
honeywell-pw-kv-physical-location-access-success-cardno
honeywell-pw-cef-physical-location-access-success-location
honeywell-pw-kv-physical-location-access-success-location
honeywell-pw-json-physical-location-access-success-badgeno
honeywell-pw-csv-physical-location-access-success-exabeam
honeywell-pw-kv-physical-location-access-success-accessgranted

physical_location-access:success (physical-access)
honeywell-pw-json-physical-location-access-areaname
honeywell-pw-xml-physical-location-access-evntdat
honeywell-pw-kv-physical-location-access-success-refidtyp
honeywell-pw-kv-physical-location-access-success-cardno
honeywell-pw-cef-physical-location-access-success-location
honeywell-pw-kv-physical-location-access-success-location
honeywell-pw-json-physical-location-access-success-badgeno
honeywell-pw-csv-physical-location-access-success-exabeam
honeywell-pw-kv-physical-location-access-success-accessgranted
T1078 - Valid Accounts
  • 9 Rules
  • 4 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Valid Accounts

Valid Accounts

Valid Accounts

Valid Accounts