-
Notifications
You must be signed in to change notification settings - Fork 4
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
7180fbf
commit a2a9b43
Showing
8,107 changed files
with
36,369 additions
and
80,517 deletions.
The diff you're trying to view is too large. We only load the first 3000 changed files.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,2 @@ | ||
|
||
.DS_Store |
Large diffs are not rendered by default.
Oops, something went wrong.
4 changes: 2 additions & 2 deletions
4
DS/AMAG/symmetry_access_control/2_ds_amag_symmetry_access_control.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,3 +1,3 @@ | ||
| Use-Case | Activity Types/Parsers | MITRE ATT&CK® TTP | Content | | ||
| Use-Case | Activity Type(Legacy Event Type)/Parsers | MITRE ATT&CK® TTP | Content | | ||
|:----:| ---- | ---- | ---- | | ||
| [Privileged Activity](../../../UseCases/uc_privileged_activity.md) | failed-physical-access<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-fail-wronghandtemplate](Ps/pC_amagsaccefphysicallocationaccessfailwronghandtemplate.md)<br> ↳[amag-sac-cef-physical-location-access-fail-inactive](Ps/pC_amagsaccefphysicallocationaccessfailinactive.md)<br> ↳[amag-sac-cef-physical-location-access-fail-atwrongdoor](Ps/pC_amagsaccefphysicallocationaccessfailatwrongdoor.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br><br> physical-access<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-success-badge-flooraccess](Ps/pC_amagsaccefphysicallocationaccesssuccessbadgeflooraccess.md)<br> ↳[amag-sac-cef-physical-location-access-success-grantedaccess](Ps/pC_amagsaccefphysicallocationaccesssuccessgrantedaccess.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br> | T1078 - Valid Accounts<br> | [<ul><li>1 Rules</li></ul>](RM/r_m_amag_symmetry_access_control_Privileged_Activity.md) | | ||
| [Privileged Activity](../../../UseCases/uc_privileged_activity.md) | physical_location-access:fail(failed-physical-access)<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-fail-wronghandtemplate](Ps/pC_amagsaccefphysicallocationaccessfailwronghandtemplate.md)<br> ↳[amag-sac-cef-physical-location-access-fail-inactive](Ps/pC_amagsaccefphysicallocationaccessfailinactive.md)<br> ↳[amag-sac-cef-physical-location-access-fail-atwrongdoor](Ps/pC_amagsaccefphysicallocationaccessfailatwrongdoor.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br><br> physical_location-access:success(physical-access)<br> ↳[amag-sac-json-physical-location-access-accessbadge](Ps/pC_amagsacjsonphysicallocationaccessaccessbadge.md)<br> ↳[amag-sac-kv-physical-location-access-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccessdatetimeoftxn.md)<br> ↳[amag-sac-kv-physical-location-access-eventcode](Ps/pC_amagsackvphysicallocationaccesseventcode.md)<br> ↳[amag-sac-cef-physical-location-access-success-badge-flooraccess](Ps/pC_amagsaccefphysicallocationaccesssuccessbadgeflooraccess.md)<br> ↳[amag-sac-cef-physical-location-access-success-grantedaccess](Ps/pC_amagsaccefphysicallocationaccesssuccessgrantedaccess.md)<br> ↳[amag-sac-kv-physical-location-access-success-datetimeoftxn](Ps/pC_amagsackvphysicallocationaccesssuccessdatetimeoftxn.md)<br> | T1078 - Valid Accounts<br> | [<ul><li>1 Rules</li></ul>](RM/r_m_amag_symmetry_access_control_Privileged_Activity.md) | |
12 changes: 12 additions & 0 deletions
12
DS/AMAG/symmetry_access_control/RM/r_m_amag_symmetry_access_control_Enrichment.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,12 @@ | ||
Rules by Product and UseCase | ||
============================ | ||
Vendor: AMAG | ||
------------ | ||
### Product: [Symmetry Access Control](../ds_amag_symmetry_access_control.md) | ||
### Use-Case: [Enrichment](../../../../UseCases/uc_enrichment.md) | ||
|
||
| Rules | Models | MITRE ATT&CK® TTPs | Activity Types | Parsers | | ||
|:-----:|:------:|:------------------:|:--------------:|:-------:| | ||
| 0 | 0 | 0 | 0 | 0 | | ||
|
||
| Event Type | Rules | Models || ---------- | ----- | ------ | |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
14 changes: 0 additions & 14 deletions
14
DS/AMD/pensando/RM/r_m_amd_pensando_Compromised_Credentials.md
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,12 @@ | ||
Rules by Product and UseCase | ||
============================ | ||
Vendor: AMD | ||
----------- | ||
### Product: [Pensando](../ds_amd_pensando.md) | ||
### Use-Case: [Enrichment](../../../../UseCases/uc_enrichment.md) | ||
|
||
| Rules | Models | MITRE ATT&CK® TTPs | Activity Types | Parsers | | ||
|:-----:|:------:|:------------------:|:--------------:|:-------:| | ||
| 0 | 0 | 0 | 0 | 0 | | ||
|
||
| Event Type | Rules | Models || ---------- | ----- | ------ | |
Oops, something went wrong.