Vendor: Dell Product: Sonicwall Rules Models MITRE ATT&CK® TTPs Activity Types Parsers 230 104 46 6 12 Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content Abnormal Authentication & Access vpn-login:fail (failed-vpn-login) ↳dell-sw-kv-vpn-login-fail-sslvpn ↳dell-sw-cef-vpn-login-fail-userloginfailed ↳dell-sw-kv-vpn-login-fail-140 endpoint-login:success (remote-logon) ↳dell-sw-cef-rdp-traffic-success-rdp vpn-login:success (vpn-login) ↳sonicwall-sw-kv-vpn-login-success-1080 ↳dell-sw-kv-vpn-login-success-netextenderconnected ↳dell-sw-cef-vpn-login-success-userloginsuccessful ↳dell-sw-kv-vpn-login-success-userloginsuccessful ↳dell-sw-kv-vpn-login-success-platformprefix ↳dell-sw-str-vpn-login-success-csacl ↳dell-sw-cef-vpn-login-success-userloginandzoneassignment vpn-logout:success (vpn-logout) ↳dell-sw-cef-vpn-logout-success-loggedout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn ↳dell-sw-kv-vpn-logout-success-infosystem ↳dell-sw-cef-vpn-logout-success-sessionend http-traffic:success (web-activity-allowed) ↳dell-sw-kv-http-session-category http-session:fail (web-activity-denied) ↳dell-sw-kv-http-session-category T1021 - Remote ServicesT1071 - Application Layer ProtocolT1071.001 - Application Layer Protocol: Web ProtocolsT1078 - Valid AccountsT1078.002 - T1078.002T1078.003 - Valid Accounts: Local AccountsT1133 - External Remote Services 55 Rules23 Models Account Manipulation vpn-logout:success (vpn-logout) ↳dell-sw-cef-vpn-logout-success-loggedout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn ↳dell-sw-kv-vpn-logout-success-infosystem ↳dell-sw-cef-vpn-logout-success-sessionend T1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate PermissionsT1484 - Group Policy Modification 7 Rules7 Models Brute Force Attack vpn-logout:success (vpn-logout) ↳dell-sw-cef-vpn-logout-success-loggedout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn ↳dell-sw-kv-vpn-logout-success-infosystem ↳dell-sw-cef-vpn-logout-success-sessionend T1110 - Brute Force 1 Rules1 Models Cryptomining http-traffic:success (web-activity-allowed) ↳dell-sw-kv-http-session-category http-session:fail (web-activity-denied) ↳dell-sw-kv-http-session-category T1071 - Application Layer ProtocolT1071.001 - Application Layer Protocol: Web ProtocolsT1496 - Resource Hijacking 1 Rules Data Access vpn-logout:success (vpn-logout) ↳dell-sw-cef-vpn-logout-success-loggedout ↳dell-sw-kv-vpn-logout-success-sslvpn ↳sonicwall-sw-kv-vpn-logout-success-sslvpn ↳dell-sw-kv-vpn-logout-success-infosystem ↳dell-sw-cef-vpn-logout-success-sessionend T1110 - Brute Force 1 Rules1 Models Privileged Activity endpoint-login:success (remote-logon) ↳dell-sw-cef-rdp-traffic-success-rdp http-traffic:success (web-activity-allowed) ↳dell-sw-kv-http-session-category http-session:fail (web-activity-denied) ↳dell-sw-kv-http-session-category T1021 - Remote ServicesT1068 - Exploitation for Privilege EscalationT1071 - Application Layer ProtocolT1071.001 - Application Layer Protocol: Web ProtocolsT1078 - Valid AccountsT1078.002 - T1078.002T1102 - Web Service 17 Rules7 Models Workforce Protection http-traffic:success (web-activity-allowed) ↳dell-sw-kv-http-session-category T1071 - Application Layer ProtocolT1071.001 - Application Layer Protocol: Web Protocols 4 Rules2 Models Next Page -->> MITRE ATT&CK® Framework for Enterprise Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Phishing: Spearphishing LinkExternal Remote ServicesValid AccountsDrive-by CompromiseExploit Public Fasing ApplicationPhishing User Execution External Remote ServicesValid AccountsAccount ManipulationAccount Manipulation: Exchange Email Delegate Permissions Valid AccountsExploitation for Privilege EscalationGroup Policy Modification Group Policy ModificationObfuscated Files or Information: Indicator Removal from ToolsValid AccountsUse Alternate Authentication MaterialUse Alternate Authentication Material: Pass the HashUse Alternate Authentication Material: Pass the TicketObfuscated Files or InformationValid Accounts: Local Accounts Brute ForceSteal or Forge Kerberos TicketsCredentials from Password StoresSteal or Forge Kerberos Tickets: Kerberoasting Remote System Discovery Remote ServicesUse Alternate Authentication MaterialInternal Spearphishing Web ServiceApplication Layer Protocol: Web ProtocolsDynamic ResolutionDynamic Resolution: Domain Generation AlgorithmsProxy: Multi-hop ProxyApplication Layer ProtocolProxy Exfiltration Over Alternative ProtocolExfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolExfiltration Over Physical Medium: Exfiltration over USBExfiltration Over C2 ChannelExfiltration Over Physical MediumExfiltration Over Web Service: Exfiltration to Cloud StorageExfiltration Over Web Service Resource Hijacking