Skip to content

Latest commit

 

History

History
22 lines (20 loc) · 15.7 KB

ds_ping_identity_ping_identity.md

File metadata and controls

22 lines (20 loc) · 15.7 KB

Vendor: Ping Identity

Product: Ping Identity

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
74 29 9 9 53
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Abnormal Authentication & Access user-password-modify:success (account-password-change)
pingidentity-pi-cef-endpoint-login-sso

user-password-reset:success (account-password-reset)
pingidentity-pi-cef-endpoint-login-sso

scheduled_task-trigger:success (app-activity)
pingidentity-pi-json-app-activity-success-deviceadded
pingidentity-pi-json-app-activity-success-deviceunpaired
pingidentity-pi-json-app-activity-apipingone
pingidentity-pi-json-app-activity-apipingone

app-login:success (app-login)
pingidentity-pi-cef-app-login-success-sso-1
pingidentity-pi-cef-app-login-success-pingfederate
pingidentity-pi-str-app-login-success-ssosuccess
pingidentity-pi-json-app-login-success-sso
pingidentity-pi-json-app-login-success-sso-1
pingidentity-pi-kv-app-login-success-sso
pingidentity-pi-cef-app-login-success-sso
pingidentity-pi-cef-app-login-sso-idp
pingidentity-pi-json-app-login-success-ssoidp
pingidentity-pi-json-app-login-ssosession
pingidentity-pi-cef-app-login-password
pingidentity-pi-cef-app-login-sso-session
pingidentity-pi-cef-app-login-sso
pingidentity-pi-json-app-activity-apipingone

endpoint-login:fail (authentication-failed)
pingidentity-pi-str-endpoint-login-fail-tid
pingidentity-pi-str-endpoint-login-fail-oauth
pingidentity-pi-str-endpoint-login-fail-inprogress
pingidentity-pi-cef-endpoint-authentication-fail-authnattemptfail
pingidentity-pi-cef-endpoint-authentication-fail-authfailure
pingidentity-pi-cef-endpoint-authentication-fail-failure
pingidentity-pi-cef-endpoint-authentication-fail-failure-1
pingidentity-pi-json-endpoint-authentication-success-fail-idp
pingidentity-pi-cef-app-authentication-fail-failure
pingidentity-pi-json-app-authentication-fail-triggeredby
pingidentity-pi-json-app-authentication-fail-authfail
pingidentity-pi-json-app-authentication-fail-ping
pingidentity-pi-json-app-authentication-fail-invalidpasscode
pingidentity-pi-json-app-authentication-fail-pingid
pingidentity-pi-json-app-authentication-fail-user
pingidentity-pi-kv-app-authentication-failure
pingidentity-pi-kv-app-authentication-failure-oauth
pingidentity-pi-json-app-authentication-fail-applicationmsg
pingidentity-pi-json-app-authentication-fail-failure-2
pingidentity-pi-cef-endpoint-login-sso

endpoint-login:success (authentication-successful)
pingidentity-pi-str-endpoint-login-success-oauth
pingidentity-pi-str-endpoint-login-success-authn
pingidentity-pi-str-endpoint-login-success-stssuccess
pingidentity-pi-str-endpoint-authentication-success-authsessionused
pingidentity-pi-str-endpoint-authentication-success-authnattemptsuccess
pingidentity-pi-str-endpoint-authentication-success-oauthsuccess
pingidentity-pi-cef-endpoint-authentication-success-authsuccess
pingidentity-pi-cef-endpoint-authentication-success-authenticated
pingidentity-pi-str-endpoint-authentication-success-authnsessioncreated
pingidentity-pi-cef-endpoint-authentication-success-authnsessioncreated
pingidentity-pi-json-endpoint-authentication-success-fail-idp
pingidentity-pi-cef-vpn-authentication-success-authnattempt
pingidentity-pi-cef-vpn-authentication-success-pingfederate
pingidentity-pingone-cef-vpn-authentication-success-ping
pingidentity-pi-cef-vpn-authentication-success-authnsessionused
pingidentity-pi-json-vpn-authentication-success-policy
pingidentity-pi-json-vpn-authentication-success-inprogress
pingidentity-pi-json-vpn-authentication-success-pingid
pingidentity-pi-json-vpn-authentication-success-authnattempt-1
pingidentity-pi-cef-endpoint-login-sso

app-login:fail (failed-app-login)
pingidentity-pi-cef-app-login-fail-sso
pingidentity-pi-kv-app-login-failure-sso
pingidentity-pi-json-app-login-fail-sso
pingidentity-pi-str-app-login-fail-ssofailure
pingidentity-pi-cef-app-login-fail-sso-1
pingidentity-pi-cef-app-login-sso-idp
pingidentity-pi-json-app-login-success-ssoidp
pingidentity-pi-json-app-login-ssosession
pingidentity-pi-cef-app-login-password
pingidentity-pi-cef-app-login-sso-session
pingidentity-pi-cef-app-login-sso
pingidentity-pi-json-app-activity-apipingone

vpn-login:success (vpn-login)
pingidentity-pingone-sk4-vpn-login-success-pingauthsuccess
T1078 - Valid Accounts
T1133 - External Remote Services
  • 16 Rules
  • 5 Models
Account Manipulation user-password-modify:success (account-password-change)
pingidentity-pi-cef-endpoint-login-sso

user-password-reset:success (account-password-reset)
pingidentity-pi-cef-endpoint-login-sso

scheduled_task-trigger:success (app-activity)
pingidentity-pi-json-app-activity-success-deviceadded
pingidentity-pi-json-app-activity-success-deviceunpaired
pingidentity-pi-json-app-activity-apipingone
pingidentity-pi-json-app-activity-apipingone
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 4 Rules
  • 1 Models
Data Leak scheduled_task-trigger:success (app-activity)
pingidentity-pi-json-app-activity-success-deviceadded
pingidentity-pi-json-app-activity-success-deviceunpaired
pingidentity-pi-json-app-activity-apipingone
pingidentity-pi-json-app-activity-apipingone
T1114 - Email Collection
T1114.003 - Email Collection: Email Forwarding Rule
  • 3 Rules
Physical Security vpn-login:success (vpn-login)
pingidentity-pingone-sk4-vpn-login-success-pingauthsuccess
T1133 - External Remote Services
  • 1 Rules
  • 1 Models
Privilege Escalation scheduled_task-trigger:success (app-activity)
pingidentity-pi-json-app-activity-success-deviceadded
pingidentity-pi-json-app-activity-success-deviceunpaired
pingidentity-pi-json-app-activity-apipingone
pingidentity-pi-json-app-activity-apipingone
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 3 Rules
  • 1 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

External Remote Services

Valid Accounts

Account Manipulation

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Valid Accounts

Email Collection

Email Collection: Email Forwarding Rule

Proxy: Multi-hop Proxy

Proxy