Skip to content

Latest commit

 

History

History
20 lines (18 loc) · 4.29 KB

ds_vmware_nsx_distributed_firewall.md

File metadata and controls

20 lines (18 loc) · 4.29 KB

Vendor: VMware

Product: NSX Distributed Firewall

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
75 24 7 2 0
Use-Case Activity Types/Parsers MITRE ATT&CK® TTP Content
Cryptomining network-connection-failed
vmware-nsxfw-cef-network-traffic-success-nsxfw

network-connection-successful
vmware-nsxfw-cef-network-traffic-success-nsxfw
T1496 - Resource Hijacking
  • 1 Rules
Lateral Movement network-connection-failed
vmware-nsxfw-cef-network-traffic-success-nsxfw

network-connection-successful
vmware-nsxfw-cef-network-traffic-success-nsxfw
T1048 - Exfiltration Over Alternative Protocol
T1071 - Application Layer Protocol
T1090.003 - Proxy: Multi-hop Proxy
T1190 - Exploit Public Fasing Application
TA0010 - TA0010
TA0011 - TA0011
  • 72 Rules
  • 24 Models
Malware network-connection-failed
vmware-nsxfw-cef-network-traffic-success-nsxfw

network-connection-successful
vmware-nsxfw-cef-network-traffic-success-nsxfw
TA0011 - TA0011
  • 6 Rules
Ransomware network-connection-failed
vmware-nsxfw-cef-network-traffic-success-nsxfw

network-connection-successful
vmware-nsxfw-cef-network-traffic-success-nsxfw
TA0011 - TA0011
  • 2 Rules

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Exploit Public Fasing Application

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy

Exfiltration Over Alternative Protocol

Resource Hijacking