Skip to content

Latest commit

 

History

History
19 lines (17 loc) · 1.48 KB

r_m_sailpoint_securityiq_Privileged_Activity.md

File metadata and controls

19 lines (17 loc) · 1.48 KB

Rules by Product and UseCase

Vendor: Sailpoint

Product: SecurityIQ

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
3 1 1 6 3
Event Type Rules Models
app-activity T1078 - Valid Accounts
APP-Account-deactivated: Activity from a de-activated user account
APP-AT-PRIV: Non-privileged user performing privileged application activity
APP-AT-PRIV: Privileged application activities
file-delete T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-permission-change T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-read T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-upload T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account
file-write T1078 - Valid Accounts
FA-Account-deactivated: File Activity from a de-activated user account