Skip to content

Latest commit

 

History

History
14 lines (12 loc) · 1.03 KB

r_m_rsa_securid_Privilege_Abuse.md

File metadata and controls

14 lines (12 loc) · 1.03 KB

Rules by Product and UseCase

Vendor: RSA

Product: SecurID

Use-Case: Privilege Abuse

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
2 2 3 1 1
Event Type Rules Models
vpn-logout T1078 - Valid Accounts
WPA-UACount: Abnormal number of privilege access events for user

T1098 - Account Manipulation
EM-InB-Perm-A: Abnormal number of mailbox permission given by user.

T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
EM-InB-Perm-A: Abnormal number of mailbox permission given by user.
WPA-UACount: Count of admin privilege events for user
EM-InB-Perm: Models the number of mailbox permissions given by this user.