Skip to content

Latest commit

 

History

History
14 lines (12 loc) · 8.96 KB

r_m_attivo_botsink_Lateral_Movement.md

File metadata and controls

14 lines (12 loc) · 8.96 KB

Rules by Product and UseCase

Vendor: Attivo

Product: BOTsink

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
48 21 5 1 0
Event Type Rules Models
network-connection-successful T1190 - Exploit Public Fasing Application
A-NET-HdPort-Inbound-F: First inbound connection on port for asset
A-NET-HdPort-Inbound-A: Abnormal inbound network connection to this port for asset
A-NET-ZdPort-Inbound-F: First inbound connection on port for zone
A-NET-ZdPort-Inbound-A: Abnormal inbound connection on port for zone
A-NET-HCountry-Inbound-F: First inbound connection from this country for asset
A-NET-HCountry-Inbound-A: Abnormal connection from this country for asset
A-NET-ZCountry-Inbound-F: First inbound connection from this country for zone
A-NET-ZCountry-Inbound-A: Abnormal connection from this country for the zone
A-NET-OCountry-Inbound-F: First inbound connection from this country for organization
A-NET-OCountry-Inbound-A: Abnormal connection from this country for the organization
A-NET-Log4j-IP: Asset was accessed by an external IP associated with Log4j exploit

TA0011 - TA0011
A-NET-HdPort-Outbound-F: First outbound connection on port for asset
A-NET-HdPort-Outbound-A: Abnormal outbound connection to destination port for the asset.
A-NET-ZdPort-Outbound-F: First outbound connection on port for zone
A-NET-ZdPort-Outbound-A: Abnormal outbound connection on port for zone
A-NET-HdPort-Inbound-F: First inbound connection on port for asset
A-NET-HdPort-Inbound-A: Abnormal inbound network connection to this port for asset
A-NET-ZdPort-Inbound-F: First inbound connection on port for zone
A-NET-ZdPort-Inbound-A: Abnormal inbound connection on port for zone
A-NET-HCountry-Inbound-F: First inbound connection from this country for asset
A-NET-HCountry-Inbound-A: Abnormal connection from this country for asset
A-NET-ZCountry-Inbound-F: First inbound connection from this country for zone
A-NET-ZCountry-Inbound-A: Abnormal connection from this country for the zone
A-NET-OCountry-Inbound-F: First inbound connection from this country for organization
A-NET-OCountry-Inbound-A: Abnormal connection from this country for the organization
A-NET-HCountry-Outbound-F: First outbound connection to this country from asset
A-NET-HCountry-Outbound-A: Abnormal outbound communication country for asset
A-NET-ZCountry-Outbound-F: First outbound connection to this country from zone
A-NET-ZCountry-Outbound-A: Abnormal outbound connection country for the zone
A-NET-OCountry-Outbound-F: First outbound connection to this country from organization
A-NET-OCountry-Outbound-A: Abnormal outbound connection country for the organization
A-NET-TI-IP-Outbound: Outbound connection to a known malicious IP
A-NET-TI-H-Outbound: Outbound connection to a known malicious host
A-NET-TI-IP-Inbound: Inbound connection from a known malicious IP
A-NET-TI-H-Inbound: Inbound connection from a known malicious host
A-NET-OdPort-Outbound-F: First outbound traffic to previously unused port for the organization.
A-NET-OdPort-Outbound-A: Abnormal outbound traffic to port for the organization.
A-NET-OdPort-Inbound-F: First inbound traffic on previously unused port for the organization.
A-NET-OdPort-Inbound-A: Abnormal inbound traffic on previously unused port for the organization.
A-NET-OsH-Outbound-A: Abnormal outbound connection for asset in the organization
A-NET-ZsH-Outbound-F: First outbound connection for asset for zone
A-NET-ZsH-Outbound-A: Abnormal outbound connection for asset for zone
A-NET-HsH-Outbound-F: First outbound connection for asset
A-NET-HsH-Outbound-A: Abnormal outbound connection for asset
A-NET-OsZ-Outbound-F: First outbound connection from zone for organization
A-NET-OsZ-Outbound-A: Abnormal outbound connection from zone for organization
A-NET-ZsZ-Outbound-F: First outbound connection from zone
A-NET-ZsZ-Outbound-A: Abnormal outbound connection from zone for asset
A-NET-HsZ-Outbound-F: First outbound connection from zone for asset
A-NET-HsZ-Outbound-A: Abnormal outbound connection from zone
A-NET-OdH-Inbound-F: First inbound connection to host for the organization.
A-NET-OdH-Inbound-A: Abnormal inbound connection to host for the organization.
A-NET-ZdH-Inbound-F: First inbound connection to host for the zone.
A-NET-OdZ-Inbound-F: First inbound connection to zone.
A-NET-OdZ-Inbound-A: Abnormal inbound connection to zone.

T1071 - Application Layer Protocol
A-NET-ZdH-Inbound-A: Abnormal inbound connection to host for the zone.

TA0010 - TA0010
A-NET-HCountry-Outbound-F: First outbound connection to this country from asset
A-NET-HCountry-Outbound-A: Abnormal outbound communication country for asset
A-NET-ZCountry-Outbound-F: First outbound connection to this country from zone
A-NET-ZCountry-Outbound-A: Abnormal outbound connection country for the zone
A-NET-OCountry-Outbound-F: First outbound connection to this country from organization
A-NET-OCountry-Outbound-A: Abnormal outbound connection country for the organization
A-NET-OdPort-Outbound-F: First outbound traffic to previously unused port for the organization.
A-NET-OdPort-Outbound-A: Abnormal outbound traffic to port for the organization.
A-NET-OsH-Outbound-A: Abnormal outbound connection for asset in the organization
A-NET-ZsH-Outbound-F: First outbound connection for asset for zone
A-NET-ZsH-Outbound-A: Abnormal outbound connection for asset for zone
A-NET-HsH-Outbound-F: First outbound connection for asset
A-NET-HsH-Outbound-A: Abnormal outbound connection for asset
A-NET-OsZ-Outbound-F: First outbound connection from zone for organization
A-NET-OsZ-Outbound-A: Abnormal outbound connection from zone for organization
A-NET-ZsZ-Outbound-F: First outbound connection from zone
A-NET-ZsZ-Outbound-A: Abnormal outbound connection from zone for asset
A-NET-HsZ-Outbound-F: First outbound connection from zone for asset
A-NET-HsZ-Outbound-A: Abnormal outbound connection from zone

T1090.003 - Proxy: Multi-hop Proxy
A-NET-TOR-Outbound: Outbound connection to a known TOR IP
A-NET-TOR-Inbound: Inbound connection from a known TOR IP
A-NET-OdZ-Inbound: Network zones with inbound communication in the organization
A-NET-ZdH-Inbound: Hosts receiving inbound communications in the zone
A-NET-OdH-Inbound: Hosts receiving inbound communications in the organization
A-NET-HsZ-Outbound: Outbound communicating zones for the asset
A-NET-ZsZ-Outbound: Outbound communicating zones
A-NET-OsZ-Outbound: Outbound communicating zones in the organization
A-NET-HsH-Outbound: Outbound communicating hosts for the asset
A-NET-ZsH-Outbound: Outbound communicating hosts in the zone
A-NET-OsH-Outbound: Outbound communicating hosts
A-NET-OdPort-Inbound: Inbound destination ports per organization
A-NET-OdPort-Outbound: Outbound destination ports per organization
A-NET-OCountry-Outbound: Outbound country per organization
A-NET-ZCountry-Outbound: Outbound country per zone
A-NET-HCountry-Outbound: Outbound country per asset
A-NET-OCountry-Inbound: Origination country per organization
A-NET-ZCountry-Inbound: Origination country per zone
A-NET-HCountry-Inbound: Inbound country per asset
A-NET-ZdPort-Inbound: Inbound destination ports per zone
A-NET-HdPort-Inbound: Inbound destination ports per asset
A-NET-ZdPort-Outbound: Outbound destination ports per zone
A-NET-HdPort-Outbound: Outbound destination ports per asset