Use-Case Activity Type (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content Compromised Credentials scheduled_task-trigger:success (app-activity) ↳sentinelone-v-cef-app-activity-success-usermodified ↳sentinelone-v-cef-app-activity-success-userdeleted ↳sentinelone-v-cef-app-activity-success-usercreatedrole app-login:success (app-login) ↳sentinelone-v-cef-app-login-success-newconsole app-login:fail (failed-app-login) ↳sentinelone-v-cef-app-login-login-failedconsole alert-trigger:success (security-alert) ↳sentinelone-v-cef-alert-trigger-success-threatdetected ↳sentinelone-v-cef-alert-trigger-success-activethreat T1027 - Obfuscated Files or InformationT1027.005 - Obfuscated Files or Information: Indicator Removal from ToolsT1078 - Valid AccountsT1133 - External Remote ServicesT1190 - Exploit Public Fasing Application 66 Rules33 Models Data Access scheduled_task-trigger:success (app-activity) ↳sentinelone-v-cef-app-activity-success-usermodified ↳sentinelone-v-cef-app-activity-success-userdeleted ↳sentinelone-v-cef-app-activity-success-usercreatedrole app-login:success (app-login) ↳sentinelone-v-cef-app-login-success-newconsole app-login:fail (failed-app-login) ↳sentinelone-v-cef-app-login-login-failedconsole T1078 - Valid Accounts 20 Rules11 Models Lateral Movement app-login:success (app-login) ↳sentinelone-v-cef-app-login-success-newconsole app-login:fail (failed-app-login) ↳sentinelone-v-cef-app-login-login-failedconsole alert-trigger:success (security-alert) ↳sentinelone-v-cef-alert-trigger-success-threatdetected ↳sentinelone-v-cef-alert-trigger-success-activethreat T1027 - Obfuscated Files or InformationT1027.005 - Obfuscated Files or Information: Indicator Removal from ToolsT1078 - Valid AccountsT1090 - ProxyT1090.003 - Proxy: Multi-hop Proxy 4 Rules Privilege Abuse user-create:success (account-creation) ↳sentinelone-v-cef-user-create-success-newuseradded scheduled_task-trigger:success (app-activity) ↳sentinelone-v-cef-app-activity-success-usermodified ↳sentinelone-v-cef-app-activity-success-userdeleted ↳sentinelone-v-cef-app-activity-success-usercreatedrole app-login:success (app-login) ↳sentinelone-v-cef-app-login-success-newconsole app-login:fail (failed-app-login) ↳sentinelone-v-cef-app-login-login-failedconsole T1078 - Valid AccountsT1098 - Account ManipulationT1098.002 - Account Manipulation: Exchange Email Delegate PermissionsT1136 - Create AccountT1136.001 - Create Account: Create: Local AccountT1136.002 - T1136.002 23 Rules9 Models Privileged Activity scheduled_task-trigger:success (app-activity) ↳sentinelone-v-cef-app-activity-success-usermodified ↳sentinelone-v-cef-app-activity-success-userdeleted ↳sentinelone-v-cef-app-activity-success-usercreatedrole app-login:success (app-login) ↳sentinelone-v-cef-app-login-success-newconsole app-login:fail (failed-app-login) ↳sentinelone-v-cef-app-login-login-failedconsole alert-trigger:success (security-alert) ↳sentinelone-v-cef-alert-trigger-success-threatdetected ↳sentinelone-v-cef-alert-trigger-success-activethreat T1068 - Exploitation for Privilege EscalationT1078 - Valid Accounts 3 Rules1 Models