Skip to content

Latest commit

 

History

History
20 lines (18 loc) · 4.16 KB

ds_iptables_iptables_fw.md

File metadata and controls

20 lines (18 loc) · 4.16 KB

Vendor: IPTables

Product: IPTables FW

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
75 24 7 2 0
Use-Case Activity Types/Parsers MITRE ATT&CK® TTP Content
Cryptomining network-connection-failed
iptables-i-kv-network-traffic-fail-deny

network-connection-successful
iptables-i-kv-network-traffic-success-accept
T1496 - Resource Hijacking
  • 1 Rules
Lateral Movement network-connection-failed
iptables-i-kv-network-traffic-fail-deny

network-connection-successful
iptables-i-kv-network-traffic-success-accept
T1048 - Exfiltration Over Alternative Protocol
T1071 - Application Layer Protocol
T1090.003 - Proxy: Multi-hop Proxy
T1190 - Exploit Public Fasing Application
TA0010 - TA0010
TA0011 - TA0011
  • 72 Rules
  • 24 Models
Malware network-connection-failed
iptables-i-kv-network-traffic-fail-deny

network-connection-successful
iptables-i-kv-network-traffic-success-accept
TA0011 - TA0011
  • 6 Rules
Ransomware network-connection-failed
iptables-i-kv-network-traffic-fail-deny

network-connection-successful
iptables-i-kv-network-traffic-success-accept
TA0011 - TA0011
  • 2 Rules

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Exploit Public Fasing Application

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy

Exfiltration Over Alternative Protocol

Resource Hijacking