Skip to content

Latest commit

 

History

History
19 lines (17 loc) · 5.23 KB

ds_cisco_cisco_secure_email.md

File metadata and controls

19 lines (17 loc) · 5.23 KB

Vendor: Cisco

Product: Cisco Secure Email

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
39 17 4 4 4
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Data Leak email-send:success (dlp-email-alert-out)
cisco-se-cef-email-send-receive-success-suser
cisco-se-cef-email-send-receive-esafriendlyfrom
cisco-secureemail-json-email-send-receive-esamid
cisco-secureemail-cef-email-send-success-logevent
cisco-secureemail-cef-email-receive-fail-secureemailgateway

email-send:fail (dlp-email-alert-out-failed)
cisco-secureemail-json-email-send-receive-esamid
cisco-secureemail-cef-email-send-success-logevent
cisco-secureemail-cef-email-receive-fail-secureemailgateway
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 34 Rules
  • 16 Models
Malware email-receive:success (dlp-email-alert-in)
cisco-se-cef-email-send-receive-success-suser
cisco-se-cef-email-send-receive-esafriendlyfrom
cisco-secureemail-json-email-send-receive-esamid
cisco-secureemail-cef-email-send-success-logevent

email-send:success (dlp-email-alert-out)
cisco-se-cef-email-send-receive-success-suser
cisco-se-cef-email-send-receive-esafriendlyfrom
cisco-secureemail-json-email-send-receive-esamid
cisco-secureemail-cef-email-send-success-logevent
cisco-secureemail-cef-email-receive-fail-secureemailgateway
T1190 - Exploit Public Fasing Application
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Valid Accounts

Exploit Public Fasing Application

Valid Accounts

Valid Accounts

Valid Accounts

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol