Use-Case Activity Type (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content Compromised Credentials scheduled_task-trigger:success (app-activity) ↳rangeraudit-ra-json-app-activity-success-enforcer app-login:success (app-login) ↳rangeraudit-ra-kv-app-login-success-ranger database-query:success (database-query) ↳rangeraudit-ra-json-database-access ↳rangeraudit-ra-cef-database-query-fail-create ↳rangeraudit-ra-cef-database-query-fail-alter ↳rangeraudit-ra-cef-database-query-fail-masknull ↳rangeraudit-ra-cef-database-query-fail-drop ↳rangeraudit-ra-cef-database-query-fail-use ↳rangeraudit-ra-cef-database-query-fail-update app-login:fail (failed-app-login) ↳rangeraudit-ra-str-app-login-fail-loginunsuccess file-read:success (file-read) ↳rangeraudit-ra-json-file-success-path file-write:success (file-write) ↳rangeraudit-ra-json-file-success-path T1003 - OS Credential DumpingT1003.001 - T1003.001T1003.002 - T1003.002T1003.003 - T1003.003T1078 - Valid AccountsT1083 - File and Directory DiscoveryT1133 - External Remote ServicesT1190 - Exploit Public Fasing ApplicationT1213 - Data from Information Repositories 93 Rules48 Models Data Access scheduled_task-trigger:success (app-activity) ↳rangeraudit-ra-json-app-activity-success-enforcer app-login:success (app-login) ↳rangeraudit-ra-kv-app-login-success-ranger database-query:success (database-query) ↳rangeraudit-ra-json-database-access ↳rangeraudit-ra-cef-database-query-fail-create ↳rangeraudit-ra-cef-database-query-fail-alter ↳rangeraudit-ra-cef-database-query-fail-masknull ↳rangeraudit-ra-cef-database-query-fail-drop ↳rangeraudit-ra-cef-database-query-fail-use ↳rangeraudit-ra-cef-database-query-fail-update app-login:fail (failed-app-login) ↳rangeraudit-ra-str-app-login-fail-loginunsuccess file-read:success (file-read) ↳rangeraudit-ra-json-file-success-path file-write:success (file-write) ↳rangeraudit-ra-json-file-success-path T1078 - Valid AccountsT1083 - File and Directory DiscoveryT1213 - Data from Information Repositories 62 Rules34 Models Privilege Abuse scheduled_task-trigger:success (app-activity) ↳rangeraudit-ra-json-app-activity-success-enforcer app-login:success (app-login) ↳rangeraudit-ra-kv-app-login-success-ranger app-login:fail (failed-app-login) ↳rangeraudit-ra-str-app-login-fail-loginunsuccess file-read:success (file-read) ↳rangeraudit-ra-json-file-success-path file-write:success (file-write) ↳rangeraudit-ra-json-file-success-path T1078 - Valid AccountsT1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate Permissions 7 Rules2 Models Privileged Activity scheduled_task-trigger:success (app-activity) ↳rangeraudit-ra-json-app-activity-success-enforcer app-login:success (app-login) ↳rangeraudit-ra-kv-app-login-success-ranger app-login:fail (failed-app-login) ↳rangeraudit-ra-str-app-login-fail-loginunsuccess file-read:success (file-read) ↳rangeraudit-ra-json-file-success-path file-write:success (file-write) ↳rangeraudit-ra-json-file-success-path T1078 - Valid Accounts 3 Rules1 Models