Skip to content

Latest commit

 

History

History
18 lines (16 loc) · 3.67 KB

ds_sysdig_sysdig_monitor.md

File metadata and controls

18 lines (16 loc) · 3.67 KB

Vendor: Sysdig

Product: Sysdig Monitor

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
30 8 5 1 1
Use-Case Activity Types/Parsers MITRE ATT&CK® TTP Content
Compromised Credentials process-alert
sysdig-monitor-json-alert-trigger-success-syscall
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
TA0002 - TA0002
  • 7 Rules
  • 2 Models
Malware process-alert
sysdig-monitor-json-alert-trigger-success-syscall
T1053.003 - T1053.003
T1190 - Exploit Public Fasing Application
T1562.004 - Impair Defenses: Disable or Modify System Firewall
TA0002 - TA0002
  • 25 Rules
  • 7 Models

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Exploit Public Fasing Application

Scheduled Task/Job

Scheduled Task/Job

Scheduled Task/Job

Impair Defenses

Obfuscated Files or Information: Indicator Removal from Tools

Impair Defenses: Disable or Modify System Firewall

Obfuscated Files or Information