Skip to content

Latest commit

 

History

History
9 lines (9 loc) · 11.4 KB

2_ds_sap_sap.md

File metadata and controls

9 lines (9 loc) · 11.4 KB
Use-Case Activity Type (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Compromised Credentials scheduled_task-trigger:success (app-activity)
sap-s-cef-user-delete-fail-audit

app-login:success (app-login)
sap-s-cef-app-login-success-dialoglogonsuccessful
sap-s-json-app-login-success-sm20logon

endpoint-login:success (authentication-successful)
sap-s-cef-endpoint-authentication-logon
sap-s-cef-endpoint-login-success-assertion-1
sap-s-cef-endpoint-login-success-assertion

app-login:fail (failed-app-login)
sap-s-cef-app-login-fail-dialoglogonfailed

file-write:success (file-write)
sap-s-cef-file-write-success-download

endpoint-login:success (remote-logon)
sap-s-cef-endpoint-login-fail-cpiclogonfail
sap-s-cef-endpoint-login-success-cpiclogonsuccessful
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1003.003 - T1003.003
T1021 - Remote Services
T1078 - Valid Accounts
T1078.002 - T1078.002
T1078.003 - Valid Accounts: Local Accounts
T1083 - File and Directory Discovery
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
T1550 - Use Alternate Authentication Material
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
  • 106 Rules
  • 53 Models
Data Access scheduled_task-trigger:success (app-activity)
sap-s-cef-user-delete-fail-audit

app-login:success (app-login)
sap-s-cef-app-login-success-dialoglogonsuccessful
sap-s-json-app-login-success-sm20logon

app-login:fail (failed-app-login)
sap-s-cef-app-login-fail-dialoglogonfailed

file-write:success (file-write)
sap-s-cef-file-write-success-download
T1078 - Valid Accounts
T1083 - File and Directory Discovery
  • 44 Rules
  • 24 Models
Lateral Movement app-login:success (app-login)
sap-s-cef-app-login-success-dialoglogonsuccessful
sap-s-json-app-login-success-sm20logon

endpoint-login:fail (authentication-failed)
sap-s-cef-endpoint-authentication-logon
sap-s-cef-endpoint-login-fail-secude

endpoint-login:success (authentication-successful)
sap-s-cef-endpoint-authentication-logon
sap-s-cef-endpoint-login-success-assertion-1
sap-s-cef-endpoint-login-success-assertion

app-login:fail (failed-app-login)
sap-s-cef-app-login-fail-dialoglogonfailed

endpoint-login:success (remote-logon)
sap-s-cef-endpoint-login-fail-cpiclogonfail
sap-s-cef-endpoint-login-success-cpiclogonsuccessful
T1018 - Remote System Discovery
T1021 - Remote Services
T1078 - Valid Accounts
T1090 - Proxy
T1090.003 - Proxy: Multi-hop Proxy
T1550 - Use Alternate Authentication Material
T1550.002 - Use Alternate Authentication Material: Pass the Hash
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
  • 29 Rules
  • 12 Models
Malware app-login:success (app-login)
sap-s-cef-app-login-success-dialoglogonsuccessful
sap-s-json-app-login-success-sm20logon

endpoint-login:success (authentication-successful)
sap-s-cef-endpoint-authentication-logon
sap-s-cef-endpoint-login-success-assertion-1
sap-s-cef-endpoint-login-success-assertion

file-write:success (file-write)
sap-s-cef-file-write-success-download

endpoint-login:success (remote-logon)
sap-s-cef-endpoint-login-fail-cpiclogonfail
sap-s-cef-endpoint-login-success-cpiclogonsuccessful
T1003 - OS Credential Dumping
T1003.002 - T1003.002
T1078 - Valid Accounts
T1505 - Server Software Component
T1505.003 - Server Software Component: Web Shell
T1547 - Boot or Logon Autostart Execution
T1547.001 - T1547.001
T1550 - Use Alternate Authentication Material
T1550.003 - Use Alternate Authentication Material: Pass the Ticket
T1558 - Steal or Forge Kerberos Tickets
TA0002 - TA0002
  • 14 Rules
  • 5 Models
Privilege Abuse user-create:success (account-creation)
sap-s-cef-user-delete-fail-audit
sap-s-cef-user-create-success-created

user-delete:success (account-deleted)
sap-s-cef-user-delete-fail-audit
sap-s-cef-user-delete-success-deleted

user-password-modify:success (account-password-change)
sap-s-cef-user-password-modify-success-changed
sap-s-cef-user-password-modify-success-loginforsso

scheduled_task-trigger:success (app-activity)
sap-s-cef-user-delete-fail-audit

app-login:success (app-login)
sap-s-cef-app-login-success-dialoglogonsuccessful
sap-s-json-app-login-success-sm20logon

app-login:fail (failed-app-login)
sap-s-cef-app-login-fail-dialoglogonfailed

file-download:success (file-download)
sap-s-cef-file-download-success-auy
sap-s-cef-file-download-success-download

file-write:success (file-write)
sap-s-cef-file-write-success-download

endpoint-login:success (remote-logon)
sap-s-cef-endpoint-login-fail-cpiclogonfail
sap-s-cef-endpoint-login-success-cpiclogonsuccessful
T1078 - Valid Accounts
T1078.002 - T1078.002
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
T1531 - Account Access Removal
  • 35 Rules
  • 15 Models
Privileged Activity scheduled_task-trigger:success (app-activity)
sap-s-cef-user-delete-fail-audit

app-login:success (app-login)
sap-s-cef-app-login-success-dialoglogonsuccessful
sap-s-json-app-login-success-sm20logon

app-login:fail (failed-app-login)
sap-s-cef-app-login-fail-dialoglogonfailed

file-download:success (file-download)
sap-s-cef-file-download-success-auy
sap-s-cef-file-download-success-download

file-write:success (file-write)
sap-s-cef-file-write-success-download

endpoint-login:success (remote-logon)
sap-s-cef-endpoint-login-fail-cpiclogonfail
sap-s-cef-endpoint-login-success-cpiclogonsuccessful
T1021 - Remote Services
T1068 - Exploitation for Privilege Escalation
T1078 - Valid Accounts
T1078.002 - T1078.002
  • 18 Rules
  • 8 Models
Ransomware app-login:success (app-login)
sap-s-cef-app-login-success-dialoglogonsuccessful
sap-s-json-app-login-success-sm20logon

endpoint-login:fail (authentication-failed)
sap-s-cef-endpoint-authentication-logon
sap-s-cef-endpoint-login-fail-secude

endpoint-login:success (authentication-successful)
sap-s-cef-endpoint-authentication-logon
sap-s-cef-endpoint-login-success-assertion-1
sap-s-cef-endpoint-login-success-assertion

app-login:fail (failed-app-login)
sap-s-cef-app-login-fail-dialoglogonfailed

file-write:success (file-write)
sap-s-cef-file-write-success-download

endpoint-login:success (remote-logon)
sap-s-cef-endpoint-login-fail-cpiclogonfail
sap-s-cef-endpoint-login-success-cpiclogonsuccessful
T1078 - Valid Accounts
T1486 - Data Encrypted for Impact
  • 3 Rules