Skip to content

Latest commit

 

History

History
14 lines (12 loc) · 887 Bytes

r_m_egnyte_egnyte_Data_Exfiltration.md

File metadata and controls

14 lines (12 loc) · 887 Bytes

Rules by Product and UseCase

Vendor: Egnyte

Product: Egnyte

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
2 1 1 1 2
Event Type Rules Models
file-write TA0002 - TA0002
FA-TEMP-DIRECTORY-F: First time process has been executed from a temporary directory by this user during file activity
FA-TEMP-DIRECTORY-A: Abnormal process has been executed from a temporary directory by this user during file activity
FA-UP-TEMP: Process executable TEMP directories for this user during file activity