-
Notifications
You must be signed in to change notification settings - Fork 4
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
f661e73
commit 86ce371
Showing
7,401 changed files
with
156,885 additions
and
9,715 deletions.
The diff you're trying to view is too large. We only load the first 3000 changed files.
There are no files selected for viewing
Large diffs are not rendered by default.
Oops, something went wrong.
3 changes: 3 additions & 0 deletions
3
DS/AMAG/symmetry_access_control/2_ds_amag_symmetry_access_control.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
| Use-Case | Activity Types/Parsers | MITRE ATT&CK® TTP | Content | | ||
|:----:| ---- | ---- | ---- | | ||
| [Privileged Activity](../../../UseCases/uc_privileged_activity.md) | failed-physical-access<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-fail-wronghandtemplate](Ps/pC_amagsaccefphysicallocationaccessfailwronghandtemplate.md)<br> ↳[amag-sac-cef-physical-location-access-fail-inactive](Ps/pC_amagsaccefphysicallocationaccessfailinactive.md)<br> ↳[amag-sac-cef-physical-location-access-fail-atwrongdoor](Ps/pC_amagsaccefphysicallocationaccessfailatwrongdoor.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br><br> physical-access<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-success-badge-flooraccess](Ps/pC_amagsaccefphysicallocationaccesssuccessbadgeflooraccess.md)<br> ↳[amag-sac-cef-physical-location-access-success-grantedaccess](Ps/pC_amagsaccefphysicallocationaccesssuccessgrantedaccess.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br> | T1078 - Valid Accounts<br> | [<ul><li>1 Rules</li></ul>](RM/r_m_amag_symmetry_access_control_Privileged_Activity.md) | |
25 changes: 25 additions & 0 deletions
25
...ymmetry_access_control/Ps/pC_amagsaccefphysicallocationaccessfailatwrongdoor.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-cef-physical-location-access-fail-atwrongdoor" | ||
Product = "Symmetry Access Control" | ||
Conditions = [ | ||
"""badge '""" | ||
"""', u'At Wrong Door', u'""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
|
||
sailpoint-iiq-events = { | ||
Vendor = Sailpoint | ||
Product = IdentityNow | ||
TimeFormat = "yyyy-MM-dd'T'HH:mm:ss.SSSZ" | ||
Fields = [ | ||
""""timestamp":"({time}\d\d\d\d-\d\d-\d\dT\d\d:\d\d:\d\d\.\d{1,3}Z)"""", | ||
""""ACCOUNT_NAME\\?":\\?"(({user_dn}(((CN|cn|uid)=[^"]+?),)?(({user_ou}(OU|ou)[^"]+?)?(DC|dc)=[\w-]+))|({account_id}[^"]+?)\\?")""", | ||
""""TARGET\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""SOURCE\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""APPLICATION\\?":\\?"({app}[^"]+?)\\?"""", | ||
""""ACTION\\?":\\?"({operation}[^"]+?)\\?"""" | ||
} | ||
``` |
25 changes: 25 additions & 0 deletions
25
...G/symmetry_access_control/Ps/pC_amagsaccefphysicallocationaccessfailinactive.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-cef-physical-location-access-fail-inactive" | ||
Product = "Symmetry Access Control" | ||
Conditions = [ | ||
"""badge '""" | ||
"""', u'Inactive', u'""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
|
||
sailpoint-iiq-events = { | ||
Vendor = Sailpoint | ||
Product = IdentityNow | ||
TimeFormat = "yyyy-MM-dd'T'HH:mm:ss.SSSZ" | ||
Fields = [ | ||
""""timestamp":"({time}\d\d\d\d-\d\d-\d\dT\d\d:\d\d:\d\d\.\d{1,3}Z)"""", | ||
""""ACCOUNT_NAME\\?":\\?"(({user_dn}(((CN|cn|uid)=[^"]+?),)?(({user_ou}(OU|ou)[^"]+?)?(DC|dc)=[\w-]+))|({account_id}[^"]+?)\\?")""", | ||
""""TARGET\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""SOURCE\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""APPLICATION\\?":\\?"({app}[^"]+?)\\?"""", | ||
""""ACTION\\?":\\?"({operation}[^"]+?)\\?"""" | ||
} | ||
``` |
25 changes: 25 additions & 0 deletions
25
...y_access_control/Ps/pC_amagsaccefphysicallocationaccessfailwronghandtemplate.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-cef-physical-location-access-fail-wronghandtemplate" | ||
Product = "Symmetry Access Control" | ||
Conditions = [ | ||
"""badge '""" | ||
"""', u'Wrong Hand Template', u'""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
|
||
sailpoint-iiq-events = { | ||
Vendor = Sailpoint | ||
Product = IdentityNow | ||
TimeFormat = "yyyy-MM-dd'T'HH:mm:ss.SSSZ" | ||
Fields = [ | ||
""""timestamp":"({time}\d\d\d\d-\d\d-\d\dT\d\d:\d\d:\d\d\.\d{1,3}Z)"""", | ||
""""ACCOUNT_NAME\\?":\\?"(({user_dn}(((CN|cn|uid)=[^"]+?),)?(({user_ou}(OU|ou)[^"]+?)?(DC|dc)=[\w-]+))|({account_id}[^"]+?)\\?")""", | ||
""""TARGET\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""SOURCE\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""APPLICATION\\?":\\?"({app}[^"]+?)\\?"""", | ||
""""ACTION\\?":\\?"({operation}[^"]+?)\\?"""" | ||
} | ||
``` |
25 changes: 25 additions & 0 deletions
25
...access_control/Ps/pC_amagsaccefphysicallocationaccesssuccessbadgeflooraccess.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-cef-physical-location-access-success-badge-flooraccess" | ||
Product = "Symmetry Access Control" | ||
Conditions = [ | ||
"""badge '""" | ||
"""', u'Floor Access', u'""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
|
||
sailpoint-iiq-events = { | ||
Vendor = Sailpoint | ||
Product = IdentityNow | ||
TimeFormat = "yyyy-MM-dd'T'HH:mm:ss.SSSZ" | ||
Fields = [ | ||
""""timestamp":"({time}\d\d\d\d-\d\d-\d\dT\d\d:\d\d:\d\d\.\d{1,3}Z)"""", | ||
""""ACCOUNT_NAME\\?":\\?"(({user_dn}(((CN|cn|uid)=[^"]+?),)?(({user_ou}(OU|ou)[^"]+?)?(DC|dc)=[\w-]+))|({account_id}[^"]+?)\\?")""", | ||
""""TARGET\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""SOURCE\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""APPLICATION\\?":\\?"({app}[^"]+?)\\?"""", | ||
""""ACTION\\?":\\?"({operation}[^"]+?)\\?"""" | ||
} | ||
``` |
25 changes: 25 additions & 0 deletions
25
...ry_access_control/Ps/pC_amagsaccefphysicallocationaccesssuccessgrantedaccess.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,25 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-cef-physical-location-access-success-grantedaccess" | ||
Product = "Symmetry Access Control" | ||
Conditions = [ | ||
"""badge '""" | ||
"""', u'Granted Access', u'""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
|
||
sailpoint-iiq-events = { | ||
Vendor = Sailpoint | ||
Product = IdentityNow | ||
TimeFormat = "yyyy-MM-dd'T'HH:mm:ss.SSSZ" | ||
Fields = [ | ||
""""timestamp":"({time}\d\d\d\d-\d\d-\d\dT\d\d:\d\d:\d\d\.\d{1,3}Z)"""", | ||
""""ACCOUNT_NAME\\?":\\?"(({user_dn}(((CN|cn|uid)=[^"]+?),)?(({user_ou}(OU|ou)[^"]+?)?(DC|dc)=[\w-]+))|({account_id}[^"]+?)\\?")""", | ||
""""TARGET\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""SOURCE\\?":\\?"(({email_address}[^@"]+@[^"]+?)|({user}[^"\s]+?))\\?"""", | ||
""""APPLICATION\\?":\\?"({app}[^"]+?)\\?"""", | ||
""""ACTION\\?":\\?"({operation}[^"]+?)\\?"""" | ||
} | ||
``` |
27 changes: 27 additions & 0 deletions
27
...G/symmetry_access_control/Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,27 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-json-physical-location-access-accessbadge" | ||
Vendor = "AMAG" | ||
Product = "Symmetry Access Control" | ||
TimeFormat = "yyyy-MM-dd'T'HH:mm:ss.SSSZ" | ||
Conditions = [ | ||
""""access_badge"""" | ||
""""txnconditionname":"""" | ||
""""cardnumber":""" | ||
] | ||
Fields = [ | ||
""""datetimeoftxn\":\"({time}\d\d\d\d-\d\d-\d\dT\d\d:\d\d:\d\d\.\d+Z)""" | ||
""""txnconditionname\":\"({action}[^\"]+)""" | ||
""""wherename\":\"({location_door}[^\"]+)""" | ||
""""firstname\":\"({first_name}[^\"]+)""" | ||
""""lastname\":\"({last_name}[^\"]+)""" | ||
""""cardnumber\":({badge_id}\d+)""" | ||
""""db_name\":\"({direction}[^\"]+)""" | ||
""""db_ip\":\"({dest_ip}((([0-9a-fA-F.]{1,4}):{1,2}){7}([0-9a-fA-F]){1,4})|(((25[0-5]|(2[0-4]|1\d|[0-9]|)\d)\.?\b){4}))(:({dest_port}\d+))?""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
|
||
|
||
} | ||
``` |
31 changes: 31 additions & 0 deletions
31
...G/symmetry_access_control/Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,31 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-kv-physical-location-access-datetimeoftxn" | ||
Vendor = "AMAG" | ||
Product = "Symmetry Access Control" | ||
TimeFormat = "yyyy-MM-dd HH:mm:ss.S" | ||
Conditions = [ | ||
""", txnconditionName ="""" | ||
""", cardNumber="""" | ||
""", employeeNumber="""" | ||
""", datetimeoftxn="""" | ||
] | ||
Fields = [ | ||
"""({host}[\w\-.]+)\s+\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d\.\d+""" | ||
"""\Wdatetimeoftxn="({time}\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d\.\d+)""" | ||
"""\Wwherename="({location_door}[^"]+)""" | ||
"""\WtxnconditionName ="({action}[^"]+)""" | ||
"""\Wlastname="({last_name}[^"]+)""" | ||
"""\WfirstName ="({first_name}[^"]+)""" | ||
"""\WcardNumber="({badge_id}[^"]+)""" | ||
"""\Wpersonaldata1="({employee_id}[^"]+)""" | ||
"""\WemployeeNumber="({employee_id}[^"]+)""" | ||
"""\Wpersonaldata2="({employee_title}[^"]+)""" | ||
"""\Wpersonaldata10="({employee_type}[^"]+)""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
} | ||
``` |
20 changes: 20 additions & 0 deletions
20
DS/AMAG/symmetry_access_control/Ps/pC_amagsackvphysicallocationaccesseventcode.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,20 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-kv-physical-location-access-eventcode" | ||
Vendor = "AMAG" | ||
Product = "Symmetry Access Control" | ||
TimeFormat = "MM/dd/yyyy HH:mm:ss a" | ||
Conditions = [ | ||
""" Device: """ | ||
""" EventCode: """ | ||
""" OPR: """ | ||
] | ||
Fields = [ | ||
"""Date:\s*({time}\d+\/\d+\/\d\d\d\d\s+\d+:\d+:\d+\s+(AM|PM|am|pm)) Device:\s*({location_door}.+?)\s+EventCode:\s*({action}\d+)\s+Name:\s*(|({full_name}[^:]*?))\s+OPR:\s*(|({operation}.+?))\s*(\d{4}\-|"|$|\w+=)""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
} | ||
``` |
28 changes: 28 additions & 0 deletions
28
...try_access_control/Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,28 @@ | ||
#### Parser Content | ||
```Java | ||
{ | ||
Name = "amag-sac-kv-physical-location-access-success-datetimeoftxn" | ||
Vendor = "AMAG" | ||
Product = "Symmetry Access Control" | ||
TimeFormat = "yyyy-MM-dd HH:mm:ss" | ||
Conditions = [ | ||
"""WhereName ="""" | ||
"""TxnConditionName ="""" | ||
"""DateTimeOfTxn="""" | ||
] | ||
Fields = [ | ||
"""[^\w]DateTimeOfTxn="({time}\d\d\d\d-\d\d-\d\d \d\d:\d\d:\d\d)""" | ||
"""[^\w]TxnConditionName ="(\s+|({result}[^"]+))"""" | ||
"""[^\w]WhereName ="(\s+|({location_door}[^"]+))"""" | ||
"""[^\w]FullName ="(\s+|({full_name}[^"]+))"""" | ||
"""[^\w]FirstName ="(\s+|({first_name}[^"]+))"""" | ||
"""[^\w]LastName ="(\s+|({last_name}[^"]+))"""" | ||
"""[^\w]CardID="(\s+|({badge_id}[^"]+))"""" | ||
"""[^\w]CardNumber="(\s+|({employee_id}[^"]+))"""" | ||
"""[^\w]EmployeeNumber="(\s+|({employee_id}[^"]+))"""" | ||
] | ||
ParserVersion = "v1.0.0" | ||
|
||
|
||
} | ||
``` |
15 changes: 15 additions & 0 deletions
15
...control/RM/r_m_amag_symmetry_access_control_Abnormal_Authentication_&_Access.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
Rules by Product and UseCase | ||
============================ | ||
Vendor: AMAG | ||
------------ | ||
### Product: [Symmetry Access Control](../ds_amag_symmetry_access_control.md) | ||
### Use-Case: [Abnormal Authentication & Access](../../../../UseCases/uc_abnormal_authentication_&_access.md) | ||
|
||
| Rules | Models | MITRE ATT&CK® TTPs | Activity Types | Parsers | | ||
|:-----:|:------:|:------------------:|:--------------:|:-------:| | ||
| 3 | 2 | 1 | 1 | 8 | | ||
|
||
| Event Type | Rules | Models | | ||
| ---- | ---- | ---- | | ||
| failed-physical-access | <b>T1078 - Valid Accounts</b><br> ↳ <b>PA-VPN-02</b>: Badge access after VPN login | • <b>PA-VPN-02</b>: Users who accessed a physical location after vpn login | | ||
| physical-access | <b>T1078 - Valid Accounts</b><br> ↳ <b>DORMANT-USER</b>: Dormant User<br> ↳ <b>AE-UA-F</b>: First activity type for user<br> ↳ <b>PA-VPN-02</b>: Badge access after VPN login | • <b>PA-VPN-02</b>: Users who accessed a physical location after vpn login<br> • <b>AE-UA</b>: All activity for users | |
15 changes: 15 additions & 0 deletions
15
...ymmetry_access_control/RM/r_m_amag_symmetry_access_control_Physical_Security.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
Rules by Product and UseCase | ||
============================ | ||
Vendor: AMAG | ||
------------ | ||
### Product: [Symmetry Access Control](../ds_amag_symmetry_access_control.md) | ||
### Use-Case: [Physical Security](../../../../UseCases/uc_physical_security.md) | ||
|
||
| Rules | Models | MITRE ATT&CK® TTPs | Activity Types | Parsers | | ||
|:-----:|:------:|:------------------:|:--------------:|:-------:| | ||
| 9 | 4 | 1 | 1 | 8 | | ||
|
||
| Event Type | Rules | Models | | ||
| ---- | ---- | ---- | | ||
| failed-physical-access | <b>T1078 - Valid Accounts</b><br> ↳ <b>FPA-UC-F</b>: Failed physical access in new location for user<br> ↳ <b>FPA-UB-F</b>: Failed physical access in new building for user<br> ↳ <b>FPA-UD-F</b>: Failed physical access to a door user has never successfully accessed<br> ↳ <b>FPA-UTi-A</b>: Failed badge access at abnormal time<br> ↳ <b>FPA-DU</b>: Failed badge access by disabled user | • <b>PA-UTi</b>: Badge access time<br> • <b>PA-UD</b>: Door level badge access by user<br> • <b>PA-UB</b>: Building level badge access by user<br> • <b>PA-UC</b>: City level badge access by user | | ||
| physical-access | <b>T1078 - Valid Accounts</b><br> ↳ <b>PA-UC-F</b>: First physical access in this location for user<br> ↳ <b>PA-UC-A</b>: Abnormal physical access in this location for user<br> ↳ <b>PA-UB-A</b>: Abnormal physical access in this building for user<br> ↳ <b>PA-UTi-A</b>: Badge access at abnormal time<br> ↳ <b>PA-MC</b>: Badge access in multiple cities within a session<br> ↳ <b>PA-DU</b>: Badge access by disabled user<br> ↳ <b>PA-WU</b>: Badge access by watchlist user | • <b>PA-UTi</b>: Badge access time<br> • <b>PA-UB</b>: Building level badge access by user<br> • <b>PA-UC</b>: City level badge access by user | |
15 changes: 15 additions & 0 deletions
15
...metry_access_control/RM/r_m_amag_symmetry_access_control_Privileged_Activity.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
Rules by Product and UseCase | ||
============================ | ||
Vendor: AMAG | ||
------------ | ||
### Product: [Symmetry Access Control](../ds_amag_symmetry_access_control.md) | ||
### Use-Case: [Privileged Activity](../../../../UseCases/uc_privileged_activity.md) | ||
|
||
| Rules | Models | MITRE ATT&CK® TTPs | Activity Types | Parsers | | ||
|:-----:|:------:|:------------------:|:--------------:|:-------:| | ||
| 1 | 0 | 1 | 1 | 8 | | ||
|
||
| Event Type | Rules | Models | | ||
| ---- | ---- | ------ | | ||
| failed-physical-access | <b>T1078 - Valid Accounts</b><br> ↳ <b>FPA-DU</b>: Failed badge access by disabled user | | | ||
| physical-access | <b>T1078 - Valid Accounts</b><br> ↳ <b>PA-DU</b>: Badge access by disabled user | | |
19 changes: 19 additions & 0 deletions
19
DS/AMAG/symmetry_access_control/ds_amag_symmetry_access_control.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,19 @@ | ||
Vendor: AMAG | ||
============ | ||
Product: Symmetry Access Control | ||
-------------------------------- | ||
| Rules | Models | MITRE ATT&CK® TTPs | Activity Types | Parsers | | ||
|:-----:|:------:|:------------------:|:--------------:|:-------:| | ||
| 12 | 6 | 1 | 1 | 8 | | ||
|
||
| Use-Case | Activity Types/Parsers | MITRE ATT&CK® TTP | Content | | ||
|:----:| ---- | ---- | ---- | | ||
| [Abnormal Authentication & Access](../../../UseCases/uc_abnormal_authentication_&_access.md) | failed-physical-access<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-fail-wronghandtemplate](Ps/pC_amagsaccefphysicallocationaccessfailwronghandtemplate.md)<br> ↳[amag-sac-cef-physical-location-access-fail-inactive](Ps/pC_amagsaccefphysicallocationaccessfailinactive.md)<br> ↳[amag-sac-cef-physical-location-access-fail-atwrongdoor](Ps/pC_amagsaccefphysicallocationaccessfailatwrongdoor.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br><br> physical-access<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-success-badge-flooraccess](Ps/pC_amagsaccefphysicallocationaccesssuccessbadgeflooraccess.md)<br> ↳[amag-sac-cef-physical-location-access-success-grantedaccess](Ps/pC_amagsaccefphysicallocationaccesssuccessgrantedaccess.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br> | T1078 - Valid Accounts<br> | [<ul><li>3 Rules</li></ul><ul><li>2 Models</li></ul>](RM/r_m_amag_symmetry_access_control_Abnormal_Authentication_&_Access.md) | | ||
| [Physical Security](../../../UseCases/uc_physical_security.md) | failed-physical-access<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-fail-wronghandtemplate](Ps/pC_amagsaccefphysicallocationaccessfailwronghandtemplate.md)<br> ↳[amag-sac-cef-physical-location-access-fail-inactive](Ps/pC_amagsaccefphysicallocationaccessfailinactive.md)<br> ↳[amag-sac-cef-physical-location-access-fail-atwrongdoor](Ps/pC_amagsaccefphysicallocationaccessfailatwrongdoor.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br><br> physical-access<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-success-badge-flooraccess](Ps/pC_amagsaccefphysicallocationaccesssuccessbadgeflooraccess.md)<br> ↳[amag-sac-cef-physical-location-access-success-grantedaccess](Ps/pC_amagsaccefphysicallocationaccesssuccessgrantedaccess.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br> | T1078 - Valid Accounts<br> | [<ul><li>9 Rules</li></ul><ul><li>4 Models</li></ul>](RM/r_m_amag_symmetry_access_control_Physical_Security.md) | | ||
[Next Page -->>](2_ds_amag_symmetry_access_control.md) | ||
|
||
MITRE ATT&CK® Framework for Enterprise | ||
-------------------------------------- | ||
| Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact | | ||
| ------------------------------------------------------------------- | --------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ----------------- | --------- | ---------------- | ---------- | ------------------- | ------------ | ------ | | ||
| [Valid Accounts](https://attack.mitre.org/techniques/T1078)<br><br> | | [Valid Accounts](https://attack.mitre.org/techniques/T1078)<br><br> | [Valid Accounts](https://attack.mitre.org/techniques/T1078)<br><br> | [Valid Accounts](https://attack.mitre.org/techniques/T1078)<br><br> | | | | | | | | |
Oops, something went wrong.