Skip to content

Latest commit

 

History

History
23 lines (21 loc) · 20.3 KB

ds_microsoft_microsoft_cas.md

File metadata and controls

23 lines (21 loc) · 20.3 KB

Vendor: Microsoft

Product: Microsoft CAS

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
207 88 32 14 55
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Abnormal Authentication & Access user-password-modify:success (account-password-change)
microsoft-mcas-cef-user-password-modify-success-changepassword
microsoft-azure-cef-user-password-modify-success-pwdchanged

scheduled_task-trigger:success (app-activity)
microsoft-exchange-cef-app-activity-exchangeonline
microsoft-exchange-cef-app-activity-newmailbox
microsoft-azure-cef-app-file-success-ldapquery
microsoft-azure-sk4-app-activity-userupdate
microsoft-mcas-cef-app-activity-success-resolvealert
microsoft-mcas-cef-app-activity-success-updateserviceprincipal
microsoft-mcas-cef-app-activity-success-addpermissiontomailbox
microsoft-mcas-cef-app-activity-success-addmembertogroup
microsoft-mcas-cef-app-activity-success-accessfolder
microsoft-mcas-cef-app-activity-success-msgdelete
microsoft-mcas-cef-app-activity-success-msgsend-1
microsoft-mcas-cef-app-activity-success-agentusercreate
microsoft-mcas-cef-app-activity-success-folderdelete
microsoft-mcas-cef-app-activity-success-msgsend
microsoft-mcas-cef-app-activity-success-foldercreate
microsoft-mcas-cef-app-activity-success-msgupdate
microsoft-mcas-cef-app-activity-success-updateuser
microsoft-mcas-cef-app-activity-success-changeuserlicense
microsoft-mcas-cef-app-activity-success-msgupdate-1
microsoft-mcas-cef-app-activity-success-addmembertorole
microsoft-mcas-cef-app-activity-success-alertdismiss
microsoft-mcas-cef-app-activity-success-movemsgtoanotherfolder
microsoft-mcas-cef-app-activity-success-skyprforbuisnessactivity
microsoft-mcas-cef-app-activity-success-commandrun
microsoft-mcas-cef-app-activity-success-impersonated
microsoft-mcas-cef-app-activity-success-suspiciousemail
microsoft-mcas-cef-app-activity-success-itemcreate
microsoft-mcas-cef-app-activity-success-grantconsoleforthirdparty
microsoft-mcas-cef-app-activity-success-folderrename
microsoft-mcas-cef-app-activity-success-movemsgtodeletedfolder
microsoft-mcas-cef-app-activity-success-msgpurge
microsoft-mcas-cef-app-activity-success-groupsettingchange
microsoft-mcas-cef-app-activity-success-foldermove
microsoft-mcas-cef-app-activity-success-msgdelete-1
microsoft-mcas-cef-app-activity-success-setcompanyinfo

app-login:success (app-login)
microsoft-mcas-cef-app-login-eventcategorylogin
microsoft-azure-cef-app-login-success-description

app-login:fail (failed-app-login)
microsoft-azure-cef-app-login-fail-dest
microsoft-mcas-cef-app-login-eventcategorylogin
T1078 - Valid Accounts
T1133 - External Remote Services
  • 15 Rules
  • 4 Models
Account Manipulation user-password-modify:success (account-password-change)
microsoft-mcas-cef-user-password-modify-success-changepassword
microsoft-azure-cef-user-password-modify-success-pwdchanged

scheduled_task-trigger:success (app-activity)
microsoft-exchange-cef-app-activity-exchangeonline
microsoft-exchange-cef-app-activity-newmailbox
microsoft-azure-cef-app-file-success-ldapquery
microsoft-azure-sk4-app-activity-userupdate
microsoft-mcas-cef-app-activity-success-resolvealert
microsoft-mcas-cef-app-activity-success-updateserviceprincipal
microsoft-mcas-cef-app-activity-success-addpermissiontomailbox
microsoft-mcas-cef-app-activity-success-addmembertogroup
microsoft-mcas-cef-app-activity-success-accessfolder
microsoft-mcas-cef-app-activity-success-msgdelete
microsoft-mcas-cef-app-activity-success-msgsend-1
microsoft-mcas-cef-app-activity-success-agentusercreate
microsoft-mcas-cef-app-activity-success-folderdelete
microsoft-mcas-cef-app-activity-success-msgsend
microsoft-mcas-cef-app-activity-success-foldercreate
microsoft-mcas-cef-app-activity-success-msgupdate
microsoft-mcas-cef-app-activity-success-updateuser
microsoft-mcas-cef-app-activity-success-changeuserlicense
microsoft-mcas-cef-app-activity-success-msgupdate-1
microsoft-mcas-cef-app-activity-success-addmembertorole
microsoft-mcas-cef-app-activity-success-alertdismiss
microsoft-mcas-cef-app-activity-success-movemsgtoanotherfolder
microsoft-mcas-cef-app-activity-success-skyprforbuisnessactivity
microsoft-mcas-cef-app-activity-success-commandrun
microsoft-mcas-cef-app-activity-success-impersonated
microsoft-mcas-cef-app-activity-success-suspiciousemail
microsoft-mcas-cef-app-activity-success-itemcreate
microsoft-mcas-cef-app-activity-success-grantconsoleforthirdparty
microsoft-mcas-cef-app-activity-success-folderrename
microsoft-mcas-cef-app-activity-success-movemsgtodeletedfolder
microsoft-mcas-cef-app-activity-success-msgpurge
microsoft-mcas-cef-app-activity-success-groupsettingchange
microsoft-mcas-cef-app-activity-success-foldermove
microsoft-mcas-cef-app-activity-success-msgdelete-1
microsoft-mcas-cef-app-activity-success-setcompanyinfo
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 4 Rules
  • 1 Models
Data Exfiltration alert-trigger:success (dlp-alert)
microsoft-mcas-json-alert-trigger-success-alertcabineteventmatchfile

file-write:success (file-write)
microsoft-azure-cef-app-file-success-ldapquery
microsoft-mcas-cef-file-write-success-appidonedrive
T1020 - Automated Exfiltration
T1071 - Application Layer Protocol
TA0002 - TA0002
TA0010 - TA0010
  • 31 Rules
  • 18 Models
Destruction of Data file-delete:success (file-delete)
microsoft-azure-cef-app-file-success-ldapquery
T1070 - Indicator Removal on Host
T1070.004 - Indicator Removal on Host: File Deletion
T1485 - Data Destruction
  • 1 Rules
Phishing email-send:success (dlp-email-alert-out)
microsoft-o365-json-email-send-success-send
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 1 Rules
  • 1 Models
Workforce Protection email-send:success (dlp-email-alert-out)
microsoft-o365-json-email-send-success-send
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 4 Rules
  • 1 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Server Software Component: Web Shell

Account Manipulation

Server Software Component

Boot or Logon Autostart Execution

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Exploitation for Privilege Escalation

Boot or Logon Autostart Execution

Obfuscated Files or Information: Indicator Removal from Tools

Indicator Removal on Host: File Deletion

Valid Accounts

Indicator Removal on Host

Obfuscated Files or Information

OS Credential Dumping

File and Directory Discovery

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Application Layer Protocol

Proxy

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol

Automated Exfiltration

Data Destruction

Data Encrypted for Impact