Skip to content

Latest commit

 

History

History
19 lines (17 loc) · 8.74 KB

ds_proofpoint_proofpoint_email_protection.md

File metadata and controls

19 lines (17 loc) · 8.74 KB

Vendor: Proofpoint

Product: Proofpoint Email Protection

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
38 16 4 4 13
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Data Leak email-send:success (dlp-email-alert-out)
proofpoint-tappod-json-email-receive-fail-emailreceived
proofpoint-tappod-json-email-send-receive-rcpts
proofpoint-tappod-json-email-send-receive-sendmailfrom
proofpoint-tappod-json-email-send-receive-sendmailto
proofpoint-tappod-cef-email-send-receive-envfrom
proofpoint-tappod-cef-email-send-receive-datarcpt
proofpoint-tappod-cef-email-send-receive-attachment
proofpoint-tappod-cef-email-send-receive-run
proofpoint-tappod-cef-email-send-receive-datafrom
proofpoint-tappod-cef-email-send-receive-msg
proofpoint-tappod-leef-email-resolvestatus
proofpoint-tappod-leef-email-externaluser

email-send:fail (dlp-email-alert-out-failed)
proofpoint-tappod-json-email-receive-fail-emailreceived
proofpoint-tappod-json-email-send-receive-rcpts
proofpoint-tappod-json-email-send-receive-sendmailfrom
proofpoint-tappod-json-email-send-receive-sendmailto
proofpoint-tappod-cef-email-send-receive-envfrom
proofpoint-tappod-cef-email-send-receive-datarcpt
proofpoint-tappod-cef-email-send-receive-attachment
proofpoint-tappod-cef-email-send-receive-run
proofpoint-tappod-cef-email-send-receive-datafrom
proofpoint-tappod-cef-email-send-receive-msg
proofpoint-tappod-leef-email-resolvestatus
proofpoint-tappod-leef-email-externaluser
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 33 Rules
  • 15 Models
Malware email-receive:success (dlp-email-alert-in)
proofpoint-tappod-json-email-receive-fail-emailreceived
proofpoint-tappod-json-email-send-receive-rcpts
proofpoint-tappod-sk4-email-receive-fail-emailreceived
proofpoint-tappod-json-email-send-receive-sendmailfrom
proofpoint-tappod-json-email-send-receive-sendmailto
proofpoint-tappod-cef-email-send-receive-envfrom
proofpoint-tappod-cef-email-send-receive-datarcpt
proofpoint-tappod-cef-email-send-receive-attachment
proofpoint-tappod-cef-email-send-receive-run
proofpoint-tappod-cef-email-send-receive-runfrom
proofpoint-tappod-cef-email-send-receive-msg
proofpoint-tappod-leef-email-resolvestatus
proofpoint-tappod-leef-email-externaluser

email-send:success (dlp-email-alert-out)
proofpoint-tappod-json-email-receive-fail-emailreceived
proofpoint-tappod-json-email-send-receive-rcpts
proofpoint-tappod-json-email-send-receive-sendmailfrom
proofpoint-tappod-json-email-send-receive-sendmailto
proofpoint-tappod-cef-email-send-receive-envfrom
proofpoint-tappod-cef-email-send-receive-datarcpt
proofpoint-tappod-cef-email-send-receive-attachment
proofpoint-tappod-cef-email-send-receive-run
proofpoint-tappod-cef-email-send-receive-datafrom
proofpoint-tappod-cef-email-send-receive-msg
proofpoint-tappod-leef-email-resolvestatus
proofpoint-tappod-leef-email-externaluser
T1190 - Exploit Public Fasing Application
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Valid Accounts

Exploit Public Fasing Application

Valid Accounts

Valid Accounts

Valid Accounts

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol