Skip to content

Latest commit

 

History

History
7 lines (7 loc) · 5.85 KB

2_ds_sentinelone_vigilance.md

File metadata and controls

7 lines (7 loc) · 5.85 KB
Use-Case Activity Type (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Compromised Credentials scheduled_task-trigger:success (app-activity)
sentinelone-v-cef-app-activity-success-usermodified
sentinelone-v-cef-app-activity-success-userdeleted
sentinelone-v-cef-app-activity-success-usercreatedrole

app-login:success (app-login)
sentinelone-v-cef-app-login-success-newconsole

app-login:fail (failed-app-login)
sentinelone-v-cef-app-login-login-failedconsole

alert-trigger:success (security-alert)
sentinelone-v-cef-alert-trigger-success-threatdetected
sentinelone-v-cef-alert-trigger-success-activethreat
T1027 - Obfuscated Files or Information
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1078 - Valid Accounts
T1133 - External Remote Services
T1190 - Exploit Public Fasing Application
  • 66 Rules
  • 33 Models
Data Access scheduled_task-trigger:success (app-activity)
sentinelone-v-cef-app-activity-success-usermodified
sentinelone-v-cef-app-activity-success-userdeleted
sentinelone-v-cef-app-activity-success-usercreatedrole

app-login:success (app-login)
sentinelone-v-cef-app-login-success-newconsole

app-login:fail (failed-app-login)
sentinelone-v-cef-app-login-login-failedconsole
T1078 - Valid Accounts
  • 20 Rules
  • 11 Models
Lateral Movement app-login:success (app-login)
sentinelone-v-cef-app-login-success-newconsole

app-login:fail (failed-app-login)
sentinelone-v-cef-app-login-login-failedconsole

alert-trigger:success (security-alert)
sentinelone-v-cef-alert-trigger-success-threatdetected
sentinelone-v-cef-alert-trigger-success-activethreat
T1027 - Obfuscated Files or Information
T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
T1078 - Valid Accounts
T1090 - Proxy
T1090.003 - Proxy: Multi-hop Proxy
  • 4 Rules
Privilege Abuse user-create:success (account-creation)
sentinelone-v-cef-user-create-success-newuseradded

scheduled_task-trigger:success (app-activity)
sentinelone-v-cef-app-activity-success-usermodified
sentinelone-v-cef-app-activity-success-userdeleted
sentinelone-v-cef-app-activity-success-usercreatedrole

app-login:success (app-login)
sentinelone-v-cef-app-login-success-newconsole

app-login:fail (failed-app-login)
sentinelone-v-cef-app-login-login-failedconsole
T1078 - Valid Accounts
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
  • 23 Rules
  • 9 Models
Privileged Activity scheduled_task-trigger:success (app-activity)
sentinelone-v-cef-app-activity-success-usermodified
sentinelone-v-cef-app-activity-success-userdeleted
sentinelone-v-cef-app-activity-success-usercreatedrole

app-login:success (app-login)
sentinelone-v-cef-app-login-success-newconsole

app-login:fail (failed-app-login)
sentinelone-v-cef-app-login-login-failedconsole

alert-trigger:success (security-alert)
sentinelone-v-cef-alert-trigger-success-threatdetected
sentinelone-v-cef-alert-trigger-success-activethreat
T1068 - Exploitation for Privilege Escalation
T1078 - Valid Accounts
  • 3 Rules
  • 1 Models