Skip to content

Latest commit

 

History

History
18 lines (16 loc) · 1.2 KB

r_m_sailpoint_securityiq_Privilege_Abuse.md

File metadata and controls

18 lines (16 loc) · 1.2 KB

Rules by Product and UseCase

Vendor: Sailpoint

Product: SecurityIQ

Use-Case: Privilege Abuse

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
1 0 1 5 2
Event Type Rules Models
file-delete T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-permission-change T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-read T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-upload T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-write T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account