Skip to content

Latest commit

 

History

History
21 lines (19 loc) · 5.16 KB

ds_postfix_postfix.md

File metadata and controls

21 lines (19 loc) · 5.16 KB

Vendor: Postfix

Product: Postfix

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
37 16 4 2 2
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Data Leak email-send:success (dlp-email-alert-out)
postfix-postfix-str-email-subject
postfix-postfix-kv-email-queue
postfix-postfix-mix-email-sent
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 32 Rules
  • 15 Models
Malware email-receive:success (dlp-email-alert-in)
postfix-postfix-str-email-subject
postfix-postfix-kv-email-queue
postfix-postfix-mix-email-sent

email-send:success (dlp-email-alert-out)
postfix-postfix-str-email-subject
postfix-postfix-kv-email-queue
postfix-postfix-mix-email-sent
T1190 - Exploit Public Fasing Application
  • 1 Rules
Phishing email-send:success (dlp-email-alert-out)
postfix-postfix-str-email-subject
postfix-postfix-kv-email-queue
postfix-postfix-mix-email-sent
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 1 Rules
  • 1 Models
Workforce Protection email-send:success (dlp-email-alert-out)
postfix-postfix-str-email-subject
postfix-postfix-kv-email-queue
postfix-postfix-mix-email-sent
T1048 - Exfiltration Over Alternative Protocol
T1048.003 - Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • 4 Rules
  • 1 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Valid Accounts

Exploit Public Fasing Application

Valid Accounts

Valid Accounts

Valid Accounts

Exfiltration Over Alternative Protocol

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol