Use-Case Activity Type (Legacy Event Type)/Parsers MITRE ATT&CK® TTP Content Compromised Credentials app-login:success (app-login) ↳wiz-w-json-app-login-success-federatedauth ↳wiz-w-json-app-login-success-fail-login app-login:fail (failed-app-login) ↳wiz-w-json-app-login-success-fail-login alert-trigger:success (security-alert) ↳wiz-w-json-alert-trigger-success-malwareinstance ↳wiz-w-json-alert-trigger-success-ddosattack ↳wiz-w-json-alert-trigger-success-cloudevents ↳wiz-w-json-alert-trigger-success-virtualmachine T1027 - Obfuscated Files or InformationT1027.005 - Obfuscated Files or Information: Indicator Removal from ToolsT1078 - Valid AccountsT1133 - External Remote ServicesT1190 - Exploit Public Fasing Application 51 Rules25 Models Lateral Movement app-login:success (app-login) ↳wiz-w-json-app-login-success-federatedauth ↳wiz-w-json-app-login-success-fail-login app-login:fail (failed-app-login) ↳wiz-w-json-app-login-success-fail-login alert-trigger:success (security-alert) ↳wiz-w-json-alert-trigger-success-malwareinstance ↳wiz-w-json-alert-trigger-success-ddosattack ↳wiz-w-json-alert-trigger-success-cloudevents ↳wiz-w-json-alert-trigger-success-virtualmachine T1027 - Obfuscated Files or InformationT1027.005 - Obfuscated Files or Information: Indicator Removal from ToolsT1078 - Valid AccountsT1090 - ProxyT1090.003 - Proxy: Multi-hop Proxy 4 Rules Malware app-login:success (app-login) ↳wiz-w-json-app-login-success-federatedauth ↳wiz-w-json-app-login-success-fail-login alert-trigger:success (security-alert) ↳wiz-w-json-alert-trigger-success-malwareinstance ↳wiz-w-json-alert-trigger-success-ddosattack ↳wiz-w-json-alert-trigger-success-cloudevents ↳wiz-w-json-alert-trigger-success-virtualmachine T1078 - Valid AccountsTA0002 - TA0002 5 Rules2 Models Privileged Activity app-login:success (app-login) ↳wiz-w-json-app-login-success-federatedauth ↳wiz-w-json-app-login-success-fail-login app-login:fail (failed-app-login) ↳wiz-w-json-app-login-success-fail-login alert-trigger:success (security-alert) ↳wiz-w-json-alert-trigger-success-malwareinstance ↳wiz-w-json-alert-trigger-success-ddosattack ↳wiz-w-json-alert-trigger-success-cloudevents ↳wiz-w-json-alert-trigger-success-virtualmachine T1068 - Exploitation for Privilege EscalationT1078 - Valid Accounts 2 Rules