Skip to content

Latest commit

 

History

History
21 lines (19 loc) · 1.77 KB

r_m_sailpoint_identitynow_Privileged_Activity.md

File metadata and controls

21 lines (19 loc) · 1.77 KB

Rules by Product and UseCase

Vendor: Sailpoint

Product: IdentityNow

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
3 1 1 8 21
Event Type Rules Models
app-activity T1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
APP-AT-PRIV: Non-privileged user performing privileged application activity
APP-AT-PRIV: Privileged application activities
app-login T1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
file-delete T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-download T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-permission-change T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-read T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-upload T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-write T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account