Skip to content

Latest commit

 

History

History
18 lines (16 loc) · 3.83 KB

ds_sysdig_sysdig_monitor.md

File metadata and controls

18 lines (16 loc) · 3.83 KB

Vendor: Sysdig

Product: Sysdig Monitor

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
30 8 8 1 0
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Compromised Credentials alert-trigger:success (process-alert)
sysdig-monitor-json-alert-trigger-success-syscall
T1027 - Obfuscated Files or Information
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
TA0002 - TA0002
  • 7 Rules
  • 2 Models
Malware alert-trigger:success (process-alert)
sysdig-monitor-json-alert-trigger-success-syscall
T1053 - Scheduled Task/Job
T1053.003 - T1053.003
T1190 - Exploit Public Fasing Application
T1562 - Impair Defenses
T1562.004 - Impair Defenses: Disable or Modify System Firewall
TA0002 - TA0002
  • 25 Rules
  • 7 Models

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Exploit Public Fasing Application

Scheduled Task/Job

Scheduled Task/Job

Scheduled Task/Job

Impair Defenses

Obfuscated Files or Information: Indicator Removal from Tools

Impair Defenses: Disable or Modify System Firewall

Obfuscated Files or Information