Skip to content

Latest commit

 

History

History
20 lines (18 loc) · 3.95 KB

ds_tripwire_enterprise_tripwire_enterprise.md

File metadata and controls

20 lines (18 loc) · 3.95 KB

Vendor: Tripwire Enterprise

Product: Tripwire Enterprise

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
5 2 2 1 2
Use-Case Activity Types (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content
Data Exfiltration alert-trigger:success (file-alert)
tripwire-t-cef-alert-trigger-success-filemodified
tripwire-t-str-alert-trigger-success-modifyfile
tripwire-t-kv-alert-trigger-success-accessed
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Malware alert-trigger:success (file-alert)
tripwire-t-cef-alert-trigger-success-filemodified
tripwire-t-str-alert-trigger-success-modifyfile
tripwire-t-kv-alert-trigger-success-accessed
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Privilege Abuse alert-trigger:success (file-alert)
tripwire-t-cef-alert-trigger-success-filemodified
tripwire-t-str-alert-trigger-success-modifyfile
tripwire-t-kv-alert-trigger-success-accessed
T1078 - Valid Accounts
  • 1 Rules
Privileged Activity alert-trigger:success (file-alert)
tripwire-t-cef-alert-trigger-success-filemodified
tripwire-t-str-alert-trigger-success-modifyfile
tripwire-t-kv-alert-trigger-success-accessed
T1078 - Valid Accounts
  • 1 Rules

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Valid Accounts

Valid Accounts

Valid Accounts

Valid Accounts