Azure Firewall Cef Check Point Cisco Asa F5 Fortinet Microsoft Threat Protection Palo Alto Networks Security Events Windows Firewall Windows Forwarded Events Windows Security Events
Impact
T1496
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Palo Alto Networks Security Events
Persistence
T1137
Cisco Asa Microsoft Threat Protection Palo Alto Networks Security Events Windows Security Events
Impact
T1561
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Security Events Windows Firewall Windows Forwarded Events Windows Security Events
Persistence
T1546
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Security Events Windows Firewall
Impact
T1496
Microsoft Threat Protection Security Events
Execution
T1203
Azure Monitor( Vminsights) DNS Microsoft Threat Protection
Command and Control
T1071
Microsoft Threat Protection Security Events Windows Firewall
Execution
T1203
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Security Events Windows Firewall
Initial Access
T1190
Aws Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Cisco Asa Microsoft Threat Protection Office365 Palo Alto Networks Security Events
Impact
T1486
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Palo Alto Networks Zscaler
Command and Control Credential Access
Awss3 Azure Monitor( Iis) Azure Monitor( Wire Data) Cef Check Point Cisco Asa Cisco Umbrella Data Connector Corelight DNS F5 Fortinet Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Nxlog DNS Logs Palo Alto Networks Security Events Windows Firewall Windows Forwarded Events Zscaler
Initial Access
T1190
Cisco Asa Microsoft Threat Protection Palo Alto Networks Security Events
Impact
T1486
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Palo Alto Networks Squid Proxy Zscaler
Command and Control
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control Execution
T1071 T1204
Cisco Asa Palo Alto Networks Security Events
Command and Control Credential Access
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Palo Alto Networks Security Events Zscaler
Command and Control Credential Access
Office365
Initial Access Collection
T1133 T1114
Azure Firewall Azure Monitor( Vminsights) Cisco Asa DNS Fortinet Office Atp Palo Alto Networks Zscaler
Command and Control Initial Access
T1071 T1566
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Palo Alto Networks Security Events Squid Proxy Zscaler
Command and Control
T1071
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Office365 Palo Alto Networks Squid Proxy Zscaler
Command and Control
T1071
Aws Awss3 Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Azure Monitor( Vminsights) Azure Monitor( Wire Data) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Palo Alto Networks Squid Proxy Zscaler
Command and Control Credential Access
Aws Awss3 Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Security Events Squid Proxy Windows Forwarded Events Zscaler
Command and Control
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Squid Proxy Zscaler
Command and Control
T1102
Awss3 Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa Cisco Umbrella Data Connector Corelight DNS F5 Fortinet Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Security Events Squid Proxy Windows Firewall Windows Forwarded Events Zscaler
Command and Control Execution
T1102 T1204
Azure Monitor( Iis) Cef Check Point Cisco Asa F5 Fortinet Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events
Collection
T1005
Microsoft Threat Protection Security Events
Execution
T1203
Office365
Credential Access
T1110
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Initial Access
T1190
Azure Monitor( Vminsights)
Command and Control
T1102
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Palo Alto Networks Zscaler
Command and Control
T1102
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Persistence
T1554
Cisco Asa Microsoft Threat Protection Palo Alto Networks Security Events
Persistence
T1053
Azure Firewall Azure Monitor( Vminsights) Cef Cef Ama Check Point Cisco Asa Cisco Asa Ama DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Security Events Windows Firewall Windows Firewall Ama Windows Forwarded Events Windows Security Events
Persistence
T1546
Aws Awss3 Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Azure Monitor( Vminsights) Azure Monitor( Wire Data) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control
Azure Active Directory Microsoft Threat Protection
Credential Access
T1110
1 Password
Defense Evasion
T1562
1 Password
Persistence
T1556
1 Password
Defense Evasion
T1556
1 Password
Defense Evasion
T1562
1 Password
Persistence
T1136
1 Password
Persistence
T1136
1 Password
Persistence
T1098
1 Password
Privilege Escalation
T1078
1 Password
Privilege Escalation
T1078
1 Password
Persistence
T1098
1 Password
Credential Access
T1555
1 Password
Defense Evasion
T1134
1 Password
Initial Access
T1078
1 Password
Persistence Defense Evasion
T1556
1 Password
Persistence
T1098
1 Password
Credential Access
T1555
1 Password
Credential Access Persistence
T1555 T1136
1 Password
Credential Access
T1555
Squid Proxy Zscaler
Initial Access
T1189
Squid Proxy Zscaler
Impact
T1496
Squid Proxy Zscaler
Execution Discovery Lateral Movement Collection Command and Control Exfiltration
T1059 T1046 T1021 T1557 T1102 T1020
Squid Proxy Zscaler
Command and Control Defense Evasion Execution
T1132 T1140 T1059
Azure Firewall
Initial Access Exfiltration Command and Control
T1190 T1041 T1568
Azure Firewall
Exfiltration Command and Control
T1041 T1571
Authomize
Initial Access
T1078
Microsoft Threat Protection
Privilege Escalation Defense Evasion
T1134
Office365
Initial Access
T1566
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Persistence
T1136
Azure Active Directory
Initial Access
T1078
Microsoft Threat Protection
Persistence
T1136
Azure Active Directory
Persistence
T1078
Security Events Windows Forwarded Events Windows Security Events
Persistence
T1098
Security Events
Credential Access
T1552
Security Events Windows Security Events
Collection
T1005
Security Events Windows Security Events
Collection
T1005
Security Events Windows Security Events
Persistence
T1098
Azure Active Directory Behavior Analytics
Persistence
T1078
Security Events Windows Security Events
Collection
T1005
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Collection
T1005
Authomize
Initial Access
T1078
Azure Active Directory
Privilege Escalation Persistence
T1098 T1078
Authomize
Initial Access Privilege Escalation
T1078
Security Events
Persistence
T1078
Waf
Defense Evasion Execution Initial Access Privilege Escalation
T1548 T1203 T1190
Waf
Defense Evasion Execution Initial Access Privilege Escalation Discovery
T1548 T1203 T1190 T1087
Azure SQL
Impact
T1485 T1565 T1491
Discovery Credential Access
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Defense Evasion
T1207
Alsid for Ad
Credential Access
T1003
Alsid for Ad
Credential Access
T1558
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1003
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Azure Active Directory Office365
Initial Access Persistence
T1199 T1136 T1078 T1098
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Initial Access
T1078
Azure Monitor( Iis)
Initial Access
T1190
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Asa Ama Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Command and Control Discovery Exfiltration Lateral Movement
T1095 T1071 T1046 T1030 T1210
Lateral Movement
T1021 T1021
Azure Active Directory
Initial Access
T1078
Apache HTTP Server Custom Logs Ama
Initial Access Lateral Movement
T1190 T1133 T1210
Apache HTTP Server Custom Logs Ama
Initial Access
T1190 T1133
Apache HTTP Server Custom Logs Ama
Initial Access
T1190 T1133
Apache HTTP Server Custom Logs Ama
Initial Access
T1190 T1133
Apache HTTP Server Custom Logs Ama
Impact Initial Access
T1498 T1190 T1133
Apache HTTP Server Custom Logs Ama
Initial Access
T1190 T1133
Apache HTTP Server Custom Logs Ama
Initial Access Exfiltration
T1190 T1133 T1048
Apache HTTP Server Custom Logs Ama
Impact Initial Access
T1498 T1190 T1133
Apache HTTP Server Custom Logs Ama
Initial Access
T1189
Apache HTTP Server Custom Logs Ama
Initial Access
T1190 T1133
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Initial Access
T1190
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Command and Control
T1071
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Initial Access
T1190 T1133
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Privilege Escalation
T1078
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Lateral Movement
T1021
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Initial Access
T1190
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Privilege Escalation Persistence
T1546
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Initial Access
T1190
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Execution
T1059
Cef Ama Trend Micro Apex One Trend Micro Apex One Ama
Command and Control
T1102
42 Crunch API Protection
Credential Access Discovery
T1110 T1087
42 Crunch API Protection
Reconnaissance
T1593 T1589
42 Crunch API Protection
Reconnaissance Collection
T1593 T1119
42 Crunch API Protection
Exfiltration
T1020
42 Crunch API Protection
Reconnaissance
T1592
42 Crunch API Protection
Initial Access Credential Access
T1190 T1528
42 Crunch API Protection
Reconnaissance Discovery
T1595 T1580 T1083
42 Crunch API Protection
Credential Access
T1110 T1555 T1187
42 Crunch API Protection
Impact
T1499
42 Crunch API Protection
Discovery Initial Access
T1087 T1190
42 Crunch API Protection
Credential Access Initial Access
T1110 T1190
Waf
Defense Evasion Execution Initial Access Reconnaissance Discovery
T1548 T1203 T1190 T1595 T1046
Waf
Defense Evasion Execution Initial Access Privilege Escalation
T1211 T1059 T1190 T0890
Waf
Initial Access Execution
T1189 T1203 T0853
Waf
Defense Evasion Execution Initial Access Privilege Escalation
T1548 T1203 T1190
Waf
Defense Evasion Execution Initial Access Privilege Escalation Discovery
T1548 T1203 T1190 T1087
Waf
Defense Evasion Execution Initial Access Privilege Escalation
T1211 T1059 T1190 T0890
Waf
Initial Access Execution
T1189 T1203 T0853
Azure Active Directory
Persistence Privilege Escalation
T1078
Azure Active Directory
Persistence Privilege Escalation
T1078
Microsoft Defender Advanced Threat Protection
Persistence
T1137
Argoscloud Security
Initial Access
T1190
Microsoft Threat Protection
Defense Evasion
T1211
Azure Active Directory
Initial Access Persistence
T1078 T1098
Azure Active Directory
Initial Access
T1078
Microsoft Threat Protection Security Events
Execution
T1204
Azure Active Directory
Initial Access
T1078
Azure Active Directory Behavior Analytics
Persistence
T1098
Azure Active Directory Behavior Analytics
Persistence
T1098
Azure Active Directory Behavior Analytics
Initial Access
T1078
Cbspolling ID Azure Functions
Initial Access
T1566
Microsoft Threat Protection
Impact
T1486
Microsoft Threat Protection
Impact
T1486
Microsoft Threat Protection
Impact
T1486
Microsoft Threat Protection
Initial Access
T1190
Microsoft Threat Protection
Persistence
T1053
Microsoft Threat Protection
Impact
T1485
Microsoft Threat Protection
Impact
T1486
Arista Awake Security Cef Ama
Arista Awake Security Cef Ama
Arista Awake Security Cef Ama
Aws Awss3
Defense Evasion
T1562 T1562
Authomize
Initial Access
T1078
Authomize
Initial Access
T1078
Execution Impact
T1496 T1559
Execution Defense Evasion
T1578 T1569
Persistence Impact
T1098 T1496
Persistence Impact
T1098 T1496
Azure Activity
Defense Evasion
T1562
Azure Key Vault
Credential Access
T1003
Azure Active Directory
Initial Access
T1199
Senserva Pro
Impact
T1529 T1498
Senserva Pro
Credential Access
T1212 T1556
Senserva Pro
Credential Access
T1056
Senserva Pro
Credential Access
T1555 T1606 T1040
Azure Activity Behavior Analytics
Lateral Movement Credential Access
T1570 T1212
Azure Activity Microsoft Threat Protection
Lateral Movement Execution
T1570 T1059
Security Events Windows Forwarded Events Windows Security Events
Execution Defense Evasion
T1059 T1027 T1140
Execution Defense Evasion
T1059 T1027 T1140
Zscaler
Command and Control
T1071
Bitglass
Initial Access
T1078
Bitglass
Initial Access
T1078
Bitglass
Credential Access
T1110
Bitglass
Exfiltration
T1567
Bitglass
Privilege Escalation
T1078
Bitglass
Initial Access
T1078
Bitglass
Exfiltration
T1567
Bitglass
Defense Evasion
T1070
Bitglass
Initial Access
T1078
Bitglass
Initial Access
T1078
Microsoft Threat Protection
Persistence Command and Control Exfiltration
T1197 T1105 T1048
Bit Sight
Execution Reconnaissance
Bit Sight
Reconnaissance Command and Control
Bit Sight
Reconnaissance Command and Control
Bit Sight
Impact Initial Access
T1491 T1190
Bit Sight
Impact Initial Access
T1491 T1190
Box Data Connector
Collection
T1530
Box Data Connector
Initial Access
T1189
Box Data Connector
Exfiltration
T1048
Box Data Connector
Initial Access
T1189
Box Data Connector
Initial Access
T1078
Box Data Connector
Exfiltration
T1537
Box Data Connector
Impact
T1485
Box Data Connector
Initial Access Persistence
T1078
Box Data Connector
Privilege Escalation
T1078
Box Data Connector
Privilege Escalation
T1078
Cbspolling ID Azure Functions
Resource Development Initial Access
T1583 T1566
Cbspolling ID Azure Functions
Resource Development Initial Access
T1583 T1566
Cbspolling ID Azure Functions
Resource Development Initial Access
T1583 T1566
Azure Active Directory
Credential Access
T1110
Azure Active Directory
Credential Access
T1110
Azure Active Directory
Credential Access
T1110
Salesforce Service Cloud
Credential Access
T1110
Azure Active Directory
Privilege Escalation
T1078
Microsoft Threat Protection
Command and Control
T1105
Windows Forwarded Events
Persistence
T1546
Security Events Windows Security Events
Defense Evasion
T1036
Security Events Windows Security Events
Defense Evasion
T1036
Security Events Windows Security Events
Defense Evasion
T1036
Aws Awss3
Defense Evasion
T1070
Aws Awss3
Privilege Escalation Lateral Movement
T1078 T1563
Azure Active Directory
Persistence Privilege Escalation
T1078
Azure Active Directory
Persistence Privilege Escalation
T1078
Aws Awss3
Persistence
T1098
Aws Awss3
Persistence
T1098
Aws Awss3
Persistence
T1098
Azure Active Directory
Privilege Escalation
T1078
Windows Forwarded Events
Impact
T1496
Azure Active Directory Cisco Asa
Initial Access
T1078
Cisco Asa
Discovery Impact
T1046 T1498
Cisco Asa
Discovery Impact
T1046 T1498
Cisco Duo Security
Impact
T1489
Cisco Duo Security
Persistence
T1078
Cisco Duo Security
Persistence Privilege Escalation
T1078
Cisco Duo Security
Impact
T1531
Cisco Duo Security
Initial Access
T1078
Cisco Duo Security
Initial Access
T1078
Cisco Duo Security
Initial Access
T1078
Cisco Duo Security
Impact
T1531
Cisco Duo Security
Initial Access
T1078
Cisco Duo Security
Initial Access
T1078
Cisco Sdwan
Initial Access
T1190 T1189
Cisco Sdwan
Initial Access
T1190 T1189
Cisco Sdwan
Resource Development
T1587
Cisco Sdwan
Command and Control
T1071
Cisco Secure Endpoint
Command and Control
T1071
Cisco Secure Endpoint
Execution
T1204
Cisco Secure Endpoint
Execution
T1204
Cisco Secure Endpoint
Execution
T1204
Cisco Secure Endpoint
Initial Access
T1190 T1133
Cisco Secure Endpoint
Initial Access
T1190 T1133
Cisco Secure Endpoint
Defense Evasion
T1562
Cisco Secure Endpoint
Command and Control
T1102
Cisco Secure Endpoint
Impact
T1486
Cisco Secure Endpoint
Initial Access
T1190 T1133
Cisco Secure Endpoint
Execution Initial Access
T1204 T1190
Cef Ama Cisco Seg Cisco Segama
Exfiltration
T1030
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cef Ama Cisco Seg Cisco Segama
Exfiltration
T1030
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cef Ama Cisco Seg Cisco Segama
Initial Access
T1566
Cisco Umbrella Data Connector
Command and Control Exfiltration
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control Initial Access
Cisco Umbrella Data Connector
Initial Access
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control Defense Evasion
Cisco Wsa Syslog Ama
Initial Access
T1566
Cisco Wsa Syslog Ama
Initial Access
T1189
Cisco Wsa Syslog Ama
Initial Access
T1189
Cisco Wsa Syslog Ama
Initial Access Command and Control
T1189 T1102
Cisco Wsa Syslog Ama
Command and Control
T1102
Cisco Wsa Syslog Ama
Initial Access
T1189
Cisco Wsa Syslog Ama
Exfiltration
T1048
Cisco Wsa Syslog Ama
Initial Access
T1189
Cisco Wsa Syslog Ama
Exfiltration
T1567
Cisco Wsa Syslog Ama
Command and Control
T1102
Cisco Wsa Syslog Ama
Initial Access
T1189
Cisco Ise Syslog Ama
Initial Access Persistence Privilege Escalation Defense Evasion Execution
T1133 T1548 T1059
Cisco Ise Syslog Ama
Defense Evasion
T1070
Cisco Ise Syslog Ama
Impact
T1490
Cisco Ise Syslog Ama
Credential Access
T1552
Cisco Ise Syslog Ama
Initial Access Persistence Privilege Escalation Defense Evasion Execution
T1133 T1548 T1059
Cisco Ise Syslog Ama
Command and Control
T1568
Cisco Ise Syslog Ama
Privilege Escalation Persistence
T1098
Cisco Ise Syslog Ama
Persistence Privilege Escalation
T1098
Cisco Ise Syslog Ama
Defense Evasion
T1562
Cisco Ise Syslog Ama
Defense Evasion
T1070
Cef Ama Claroty Claroty Ama
Impact
T1529
Cef Ama Claroty Claroty Ama
Impact
T1529
Cef Ama Claroty Claroty Ama
Initial Access
T1190 T1133
Cef Ama Claroty Claroty Ama
Initial Access
T1190 T1133
Cef Ama Claroty Claroty Ama
Initial Access
T1190 T1133
Cef Ama Claroty Claroty Ama
Initial Access
T1190 T1133
Cef Ama Claroty Claroty Ama
Discovery
T1018
Cef Ama Claroty Claroty Ama
Discovery
T1018
Cef Ama Claroty Claroty Ama
Discovery
T1018
Cef Ama Claroty Claroty Ama
Discovery
T1018
Microsoft Threat Protection
Defense Evasion
T1070
Symantec Vip Syslog Ama
Credential Access
T1110
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Persistence Command and Control
T1505 T1071
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Aws
Privilege Escalation
T1484
Cbspolling ID Azure Functions
Initial Access
T1195
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Security Events
Privilege Escalation
T1543
Microsoft Threat Protection Security Events
Persistence
T1574
Defense Evasion Impact
T1578 T1531
Microsoft Threat Protection
Persistence Privilege Escalation
T1546
Cbspolling ID Azure Functions
Reconnaissance
T1589
Azure Active Directory
Defense Evasion
T1078
Cef Ama Contrast Protect Contrast Protect Ama
Initial Access Exfiltration
T1566
Cef Ama Contrast Protect Contrast Protect Ama
Initial Access Exfiltration
T1566
Cef Ama Contrast Protect Contrast Protect Ama
Initial Access Exfiltration
T1566
Cef Ama Contrast Protect Contrast Protect Ama
Initial Access Exfiltration
T1566
Hvpolling ID Azure Functions
Credential Access
T1606
Hvpolling ID Azure Functions
Initial Access
T1190 T1566
Hvpolling ID Azure Functions
Credential Access
T1539
Corelight
Command and Control
T1568
Corelight
Defense Evasion Command and Control
T1090
Corelight
Credential Access
T1187
Corelight
Exfiltration
T1567
Corelight
Exfiltration
T1030
Corelight
Initial Access
T1566
Corelight
Initial Access
T1566
Corelight
Persistence
T1505
Corelight
Persistence
T1505
Corelight
Initial Access
T1566
Azure Active Directory Identity Protection Behavior Analytics
Initial Access
T1078
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Azure Activity
Defense Evasion
T1578
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Azure Active Directory
Credential Access Persistence Privilege Escalation
T1555 T1098
Security Events Windows Security Events
Credential Access
T1003
Security Events Windows Security Events
Credential Access
T1003
Azure SQL
Initial Access
T1190
Check Point Fortinet Palo Alto Networks Zscaler
Exfiltration Command and Control
T1567 T1102
Check Point Fortinet Palo Alto Networks Zscaler
Exfiltration Command and Control
T1567 T1102
Cef Ama Crowd Strike Falcon Endpoint Protection Crowd Strike Falcon Endpoint Protection Ama
Cef Ama Ridge Bot Data Connector
Execution Initial Access Privilege Escalation
T1189 T1059 T1053 T1548
Cef Ama Crowd Strike Falcon Endpoint Protection Crowd Strike Falcon Endpoint Protection Ama
Vmware Carbon Black
Lateral Movement
T1210
Aws Azure Active Directory Behavior Analytics Microsoft Threat Protection
Credential Access
T1110
Awss3 Gcpaudit Logs Definition
Initial Access Execution Persistence Privilege Escalation Credential Access Discovery Lateral Movement
T1566 T1059 T1078 T1547 T1548 T1069 T1552
Azure Active Directory Identity Protection Gcpaudit Logs Definition Microsoft Cloud App Security Microsoft Defender Advanced Threat Protection Microsoft Threat Protection
Initial Access Execution Persistence Privilege Escalation Credential Access Discovery
T1566 T1059 T1078 T1046 T1547 T1548 T1069 T1552
Awss3 Azure Active Directory
Credential Access Initial Access
T1557 T1110 T1110 T1110 T1606 T1556 T1133
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Cyber Ark Epm
Execution
T1204
Cyber Ark Epm
Defense Evasion
T1127
Cyber Ark Epm
Execution
T1204
Cyber Ark Epm
Execution
T1204
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cyber Ark Epm
Execution Defense Evasion Command and Control
T1204 T1036 T1095
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cynerio Security Events
Lateral Movement
T0866
Cynerio Security Events
Credential Access
T1552
Cynerio Security Events
Credential Access
T1552
Cynerio Security Events
Lateral Movement
T0866
Cynerio Security Events
Lateral Movement
T0866
Defense Evasion Impact
T1578 T1531
Dataminr Pulse Alerts
Persistence
T1546
Microsoft Threat Protection
Lateral Movement
T1021
Security Events Windows Security Events
Lateral Movement
T1021
Microsoft Threat Protection
Execution Collection Exfiltration
T1059 T1005 T1020
Microsoft Threat Protection
Impact
T1485
Io T
Inhibit Response Function
T0814
Azure Active Directory
Initial Access Exfiltration Command and Control
Authomize
Privilege Escalation
T1078
Azure Active Directory
Initial Access
T1078 T1133
Azure Security Center Microsoft Defender for Cloud Tenant Based
Impact
T1496
Command and Control
T1568 T1573 T1008
Command and Control
T1568 T1573 T1008
Command and Control
T1568 T1008
Command and Control
T1568 T1008
Initial Access Command and Control
T1190 T1133 T1071
Initial Access Impact
T1190 T1133 T1498
Azure Active Directory
Initial Access
T1078 T1133
Initial Access Command and Control
T1190 T1133 T1071
Initial Access Execution
T1190 T1133 T1059
Cisco Secure Endpoint Crowd Strike Falcon Endpoint Protection Microsoft Threat Protection Sentinel One Trend Micro Apex One Trend Micro Apex One Ama Vmware Carbon Black
Impact
T1490
Microsoft Threat Protection
Execution
T1204
Azure Active Directory
Persistence Privilege Escalation
T1098 T1078
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Asa Ama Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Command and Control Lateral Movement Execution Initial Access
T1095 T1059 T1203 T1190
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Asa Ama Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Command and Control Execution Initial Access
T1095 T1059 T1203 T1190
Discovery Command and Control Credential Access
T1083 T1071 T1110
Microsoft Threat Protection
Credential Access
T1558
Defense Evasion Persistence Command and Control
T1036 T1505 T1071
Exfiltration Command and Control
T1041 T1071 T1001
Initial Access
T1190 T1133
Cisco Secure Endpoint Crowd Strike Falcon Endpoint Protection Microsoft Threat Protection Sentinel One Trend Micro Apex One Trend Micro Apex One Ama Vmware Carbon Black
Persistence Privilege Escalation
T1547
Azure Active Directory
Defense Evasion Exfiltration Command and Control
Cisco Secure Endpoint Crowd Strike Falcon Endpoint Protection Microsoft Threat Protection Sentinel One Trend Micro Apex One Trend Micro Apex One Ama Vmware Carbon Black
Persistence Privilege Escalation Defense Evasion
T1547 T1112
Command and Control
T1102 T1071
Azure Active Directory
Discovery
T1046
Microsoft Threat Protection
Execution Defense Evasion Discovery
T1059 T1574 T1087 T1082
Initial Access
T1190 T1133
Initial Access Command and Control
T1190 T1133 T1071
Initial Access Persistence Execution
T1133 T1203 T1566
Cisco Secure Endpoint Crowd Strike Falcon Endpoint Protection Microsoft Threat Protection Sentinel One Trend Micro Apex One Trend Micro Apex One Ama Vmware Carbon Black
Defense Evasion
T1562
Cisco Secure Endpoint Crowd Strike Falcon Endpoint Protection Microsoft Threat Protection Sentinel One Trend Micro Apex One Trend Micro Apex One Ama Vmware Carbon Black
Defense Evasion
T1562
Azure Active Directory Azure Activity Azure Security Center Office365
Initial Access Privilege Escalation
T1078 T1548
Security Events Windows Security Events
Lateral Movement
T1021
Microsoft Threat Protection
Impact
T1490
Microsoft Threat Protection
Impact
T1490
Microsoft Threat Protection
Impact
T1490
Syslog Syslog Ama
Lateral Movement Execution
T1072
Asim DNS Activity Logs DNS
Command and Control
T1071
Syslog Syslog Ama
Command and Control
T1071
Azure Activity
Command and Control
T1071
Asim DNS Activity Logs DNS
Command and Control
T1071
Cef Cef Ama
Resource Development
T1587
Microsoft Defender Advanced Threat Protection Microsoft Threat Protection
Credential Access Execution
T1569 T1003
Credential Access Execution
T1569 T1003
Microsoft Threat Protection Security Events Windows Security Events
Exfiltration Defense Evasion
T1048 T1562
Microsoft Threat Protection Security Events Windows Security Events
Persistence
T1098
Microsoft Threat Protection Security Events Windows Security Events
Impact
T1486
Microsoft Threat Protection Security Events Windows Security Events
Discovery
T1482
Microsoft Threat Protection
Impact
T1486
Okta Sso Okta Ssov2
Persistence
T1098
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Digital Guardian Dlp Syslog Ama
Exfiltration
T1048
Microsoft Threat Protection
Defense Evasion
T1562
Microsoft Threat Protection
Defense Evasion
T1562
Cef Ama Zscaler Zscaler Ama
Command and Control
T1071
Squid Proxy Zscaler
Command and Control
T1071
Prancer Log Data
Reconnaissance
T1595
Azure Active Directory
Credential Access
T1110
Hvpolling ID Azure Functions
Collection
T1114
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Windows Forwarded Events Zscaler
Impact
T1496
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Zscaler
Exfiltration
T1048
Cbspolling ID Azure Functions
Reconnaissance Initial Access
T1590 T1566
Microsoft Threat Protection
Execution Defense Evasion
T1059 T1562
Microsoft Threat Protection
Credential Access
T1003
Azure SQL
Initial Access
T1190
Security Events
Persistence
T1098
Security Events Windows Security Events
Credential Access
T1003
Dynatrace Problems
Defense Evasion Execution Impact Initial Access Lateral Movement Persistence Privilege Escalation
Dynatrace Attacks
Execution Impact Initial Access Privilege Escalation
T1059 T1565 T1190 T1068
Dynatrace Runtime Vulnerabilities
Defense Evasion Execution Impact Initial Access Lateral Movement Persistence Privilege Escalation
Dynatrace Runtime Vulnerabilities
Defense Evasion Execution Impact Initial Access Lateral Movement Persistence Privilege Escalation
Dynatrace Runtime Vulnerabilities
Defense Evasion Execution Impact Initial Access Lateral Movement Persistence Privilege Escalation
Windows Security Events
Initial Access
T1078
Egress Defend
Execution Initial Access Persistence Privilege Escalation
T1204 T0853 T0863 T1566 T1546
Egress Defend
Execution
T1204 T0853
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Privilege Escalation
T1068 T1078
Authomize
Privilege Escalation Persistence
T1098
Azure Active Directory
Persistence Privilege Escalation
T1078
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Windows Firewall
Command and Control Credential Access
T1071 T1003
Sophos Xgfirewall Syslog Ama
Impact
T1499
Symantec Endpoint Protection Syslog Ama
Exfiltration Command and Control Lateral Movement
T1041 T1132 T1001 T1021
Symantec Proxy Sg Syslog Ama
Defense Evasion Command and Control
T1090 T1562
Symantec Vip Syslog Ama
Credential Access
T1110
Io T
Impair Process Control
T0806
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Asa Ama Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Impact
T1499
Squid Proxy Zscaler
Persistence Credential Access
T1110 T1556
Infoblox Nios Syslog Ama
Command and Control
T1568 T1008
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Zscaler
Command and Control
T1568 T1008
Security Events Windows Security Events
Collection Discovery
T1039 T1135
Security Events Windows Security Events
Credential Access
T1110
Office365
Defense Evasion
T1562
Security Events Windows Security Events
Initial Access
T1190
Azure Monitor( Iis)
Initial Access
T1190
Azure Monitor( Iis) Microsoft Threat Protection
Execution
T1059 T1059
Azure SQL
Initial Access
T1190
Microsoft Threat Protection
Execution
T1203
Cbspolling ID Azure Functions
Initial Access
T1566
Azure Active Directory
Defense Evasion
T1036
Azure Active Directory
Credential Access
T1528
Hvpolling ID Azure Functions
Initial Access
T1190
Cbspolling ID Azure Functions
Resource Development
T1586
Hvpolling ID Azure Functions
Resource Development
T1586
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Credential Access Persistence
T1098 T1556
Azure Active Directory
Persistence
T1136
Office365
Persistence
T1136
Aws Azure Active Directory
Initial Access Credential Access
T1078 T1110
Aws Azure Active Directory
Initial Access Credential Access
T1078 T1110
Azure Active Directory Security Events Syslog Windows Forwarded Events Windows Security Events
Initial Access Credential Access
T1078 T1110
Azure Active Directory Security Events Syslog Windows Forwarded Events Windows Security Events
Initial Access Credential Access
T1078 T1110
Azure Active Directory
Credential Access
T1110
Okta Sso Okta Ssov2
Credential Access
T1110
Security Events Windows Forwarded Events Windows Security Events
Credential Access
T1110
Syslog Syslog Ama
Credential Access
T1110
Azure Active Directory Last Pass
Initial Access
T1078 T1190
Security Events
Defense Evasion
T1564
Microsoft Threat Protection
Exfiltration
T1041
Azure SQL
Initial Access
T1190
Azure SQL
Initial Access
T1190
Azure Active Directory
Defense Evasion
T1550
Flare
Credential Access
T1555
Flare
Credential Access
T1110
Flare
Resource Development
T1583
Prancer Log Data
Reconnaissance
T1595
Fortinet
Command and Control
T1071 T1571
Fortinet Forti Web Ama Forti Web
Initial Access
T1190 T1133
Waf
Defense Evasion Execution Initial Access Privilege Escalation
T1211 T1059 T1190 T0890
Waf
Initial Access Execution
T1189 T1203 T0853
Aws Awss3
Privilege Escalation Defense Evasion
T1484
Azure Active Directory
Defense Evasion
T1550
Security Events Windows Forwarded Events Windows Security Events
Lateral Movement
T1210
Security Events Windows Security Events
Lateral Movement
T1210
Gcpiamdata Connector
Defense Evasion
T1562
Gcpiamdata Connector
Defense Evasion
T1550
Gcpiamdata Connector
Privilege Escalation
T1078
Gcpiamdata Connector
Lateral Movement
T1550
Gcpiamdata Connector
Persistence
T1136
Gcpiamdata Connector
Lateral Movement
T1550
Gcpiamdata Connector
Discovery
T1069
Gcpiamdata Connector
Discovery
T1069
Gcpiamdata Connector
Discovery
T1087
Gcpiamdata Connector
Discovery
T1069
Initial Access Execution Privilege Escalation Defense Evasion Credential Access Lateral Movement
T1190 T1203 T1068 T1211 T1212 T1210
Azure Active Directory
Credential Access
T1110
Syslog
Credential Access
T1110
Syslog
Credential Access
T1110
Syslog
Persistence Defense Evasion Credential Access
T1556
Azure Active Directory
Credential Access
T1110
Syslog Threat Intelligence Threat Intelligence Taxii
Initial Access
T1078
Gcpdnsdata Connector
Privilege Escalation
T1068
Gcpdnsdata Connector
Privilege Escalation
T1068
Gcpdnsdata Connector
Privilege Escalation
T1068
Gcpdnsdata Connector
Initial Access Credential Access
T1566 T1187
Gcpdnsdata Connector
Command and Control
T1095
Gcpdnsdata Connector
Initial Access
T1195
Gcpdnsdata Connector
Command and Control
T1095
Gcpdnsdata Connector
Command and Control
T1095
Gcpdnsdata Connector
Exfiltration
T1567
Gcpdnsdata Connector
Command and Control
T1095
Gcpdnsdata Connector
Command and Control
T1095
Cef Cef Ama Grey Noise2 Sentinel API Threat Intelligence
Command and Control
T1071
Asim DNS Activity Logs DNS Grey Noise2 Sentinel API Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Asa Ama Cisco Meraki Corelight Fortinet Grey Noise2 Sentinel API Microsoft Defender Threat Intelligence Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Command and Control
T1071
Grey Noise2 Sentinel API Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Active Directory Grey Noise2 Sentinel API Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Azure Active Directory Office365
Initial Access
T1566
Azure Active Directory Office365
Defense Evasion
T1562
Azure Active Directory Office365
Persistence
T1136
Azure Active Directory Office365
Collection Exfiltration
T1114 T1020
Azure Active Directory Office365
Persistence Defense Evasion
T1098 T1078
Azure Active Directory Office365
Impact
T1485 T1489
Azure Active Directory Office365
Collection Exfiltration
T1114 T1020
Azure Active Directory Office365
Command and Control Lateral Movement
T1105 T1570
Azure Active Directory
Command and Control
T1105
Azure Active Directory
Collection Exfiltration
T1114 T1020
Azure Active Directory Office365
Persistence Defense Evasion
T1098 T1562
Azure Active Directory
Execution Persistence Collection
T1059 T1098 T1114
Azure Active Directory Office365
Persistence Collection
T1098 T1114
Azure Active Directory Office365
Exfiltration
T1030
Azure Active Directory Office365
Exfiltration
T1020
Azure Active Directory Office365
Exfiltration
T1020
Azure Active Directory Office365
Exfiltration
T1030
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Exfiltration
T1030
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Persistence
T1078
Google Workspace Reports API
Persistence
T1098
Google Workspace Reports API
Initial Access
T1190 T1133
Google Workspace Reports API
Collection
T1114
Google Workspace Reports API
Defense Evasion Lateral Movement
T1550
Google Workspace Reports API
Persistence Collection
T1185 T1176
Google Workspace Reports API
Credential Access
T1110
Google Workspace Reports API
Initial Access
T1566
Google Workspace Reports API
Credential Access
T1111
Google Workspace Reports API
Defense Evasion Persistence
T1036 T1554
Google Workspace Reports API
Persistence
T1098
Hvpolling ID Azure Functions
Initial Access
T1190 T1566
Hvpolling ID Azure Functions
Credential Access Collection
T1557
Hvpolling ID Azure Functions
Credential Access Collection
T1557
Hvpolling ID Azure Functions
Reconnaissance
T1592
Hvpolling ID Azure Functions
Initial Access
T1189
Hvpolling ID Azure Functions
Initial Access
T1189
Hvpolling ID Azure Functions
Initial Access
T1189
Hvpolling ID Azure Functions
Initial Access
T1189
Azure Monitor( Iis)
Initial Access
T1190
Azure Monitor( Iis)
Credential Access
T1110
Azure Monitor( Iis)
Credential Access
T1110
Qualys Vulnerability Management
Initial Access
T1190
Azure Active Directory Office365
Initial Access Persistence Collection
T1078 T1098 T1114
Cyberpion Security Logs
Initial Access
T1190 T1195
Okta Sso Okta Ssov2
Persistence
T1098
Aws Azure Active Directory
Privilege Escalation
T1134 T1078 T1078
Last Pass
Credential Access Discovery
T1555 T1087
Microsoft Threat Protection
Persistence Privilege Escalation Defense Evasion
T1574
Authomize
Initial Access
T1078
Authomize
Privilege Escalation Persistence
T1098
Authomize
Initial Access
T1078
Initial Access Credential Access
T1190 T1133 T1528
Microsoft Threat Protection Security Events
Lateral Movement
T1570
Microsoft Threat Protection Security Events Windows Security Events
Initial Access
T1190
Defense Evasion Impact
T1578 T1531
Io T
Impair Process Control
T0855
Illumio Saa Sdata Connector
Defense Evasion
T1562
Illumio Saa Sdata Connector
Defense Evasion
T1562
Illumio Saa Sdata Connector
Defense Evasion
T1562
Illumio Saa Sdata Connector
Defense Evasion
T1562
Illumio Saa Sdata Connector
Defense Evasion
T1562
Illumio Saa Sdata Connector
Defense Evasion
T1562
Cef Ama Illusive Illusive Attack Management System Ama
Persistence Privilege Escalation Defense Evasion Credential Access Lateral Movement
T1078 T1098 T1548 T1021
Defense Evasion Persistence
T1562 T1547
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Cef Ama Infoblox Cloud Data Connector Infoblox Cloud Data Connector Ama
Impact
T1498 T1565
Cef Ama Infoblox Cloud Data Connector Infoblox Cloud Data Connector Ama
Impact
T1498 T1565
Cef Ama Infoblox Cloud Data Connector Infoblox Cloud Data Connector Ama
Impact
T1498 T1565
Cef Ama Infoblox Cloud Data Connector Infoblox Cloud Data Connector Ama
Impact
T1498 T1565
Cef Ama Infoblox Cloud Data Connector Infoblox Cloud Data Connector Ama
Impact
T1498 T1565
Infoblox Socinsights Data Connector API
Impact
T1498 T1565
Infoblox Socinsights Data Connector API
Impact
T1498 T1565
Cef Ama Infoblox Socinsights Data Connector Ama Infoblox Socinsights Data Connector Legacy
Impact
T1498 T1565
Infoblox Socinsights Data Connector Ama Infoblox Socinsights Data Connector Legacy
Impact
T1498 T1565
Cef Cef Ama Infoblox Cloud Data Connector Infoblox Cloud Data Connector Ama Threat Intelligence
Impact
T1498 T1565
Cef Ama Infoblox Cloud Data Connector Infoblox Cloud Data Connector Ama Threat Intelligence
Impact
T1498 T1565
Cef Ama Infoblox Cloud Data Connector Infoblox Cloud Data Connector Ama Syslog Threat Intelligence
Impact
T1498 T1565
Microsoft Threat Protection
Command and Control Defense Evasion
T1105 T1564 T1027 T1140
Azure Active Directory Identity Protection Azure Security Center Io T Microsoft Cloud App Security Microsoft Defender Advanced Threat Protection Office Atp
Execution
T1204
Azure Active Directory Identity Protection Azure Security Center Io T Microsoft Cloud App Security Microsoft Defender Advanced Threat Protection Office Atp
Execution
T1204
Azure Active Directory
Execution
T1204
Azure Active Directory Azure Information Protection
Exfiltration
T1567
Io T
Lateral Movement
T0886
Check Point Fortinet Microsoft Threat Protection Palo Alto Networks Zscaler
Exfiltration Command and Control
T1041 T1071
Azure Active Directory Palo Alto Networks
Initial Access Credential Access
T1078 T1110
Jamf Protect
Initial Access
T1133
Microsoft Threat Protection
Execution
T1059
Jira Audit API
Privilege Escalation
T1078
Jira Audit API
Initial Access
T1078
Jira Audit API
Persistence Privilege Escalation
T1078
Jira Audit API
Persistence
T1078
Jira Audit API
Impact
T1531
Jira Audit API
Impact
T1531
Jira Audit API
Impact
T1531
Jira Audit API
Impact
T1531
Jira Audit API
Persistence
T1078
Jira Audit API
Collection
T1213
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Palo Alto Networks Zscaler
Command and Control
T1071
Vmware Carbon Black
Execution
T1204
Authomize
Privilege Escalation Persistence
T1098
Security Events Windows Security Events
Lateral Movement
T1021
Microsoft Threat Protection
Credential Access
T1003
Cbspolling ID Azure Functions
Credential Access Resource Development
Microsoft Cloud App Security
Command and Control Exfiltration
T1071 T1567
Microsoft Threat Protection
Persistence
T1098
Aws Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Azure Monitor( Vminsights) Azure Monitor( Wire Data) Cisco Asa Cisco Asa Ama DNS Microsoft Threat Protection Office365 Palo Alto Networks Security Events
Command and Control
T1071
Aws Awss3
Defense Evasion Privilege Escalation Persistence Initial Access
T1078
Lookout API
Discovery
T1057
Microsoft Threat Protection
Credential Access
T1003
Check Point Fortinet Office Atp Palo Alto Networks Zscaler
Privilege Escalation
T1078
Office365
Collection Exfiltration
T1114 T1020
Azure Active Directory
Persistence
T1098
Aws Azure Active Directory Azure Monitor( Iis) Office365 Waf
Initial Access Command and Control Execution
T1189 T1071 T1203
Office365
Persistence Defense Evasion
T1098 T1078
Office365
Persistence Defense Evasion
T1098 T1078
Azure Monitor( Iis) Microsoft Defender Advanced Threat Protection
Persistence
T1505
Proofpoint Tap
Initial Access
T1566
Symantec Endpoint Protection Syslog Ama
Execution
T1204
Security Events Windows Forwarded Events Windows Security Events
Defense Evasion
T1564
Proofpoint Tap
Initial Access
T1566
Azure Activity
Impact
T1485
Microsoft Cloud App Security Microsoft Threat Protection
Exfiltration
T1052
Azure Key Vault
Credential Access
T1003
Microsoft Threat Protection
Defense Evasion
T1036
MC Afeee Po Syslog Ama
Defense Evasion
T1562
MC Afeee Po Syslog Ama
Defense Evasion
T1562 T1070
MC Afeee Po Syslog Ama
Defense Evasion
T1562
MC Afeee Po Syslog Ama
Defense Evasion
T1562 T1070
MC Afeee Po Syslog Ama
Defense Evasion
T1562 T1070
MC Afeee Po Syslog Ama
Defense Evasion Command and Control
T1562 T1071
MC Afeee Po Syslog Ama
Defense Evasion
T1562 T1070
MC Afeee Po Syslog Ama
Initial Access Persistence Defense Evasion Privilege Escalation
T1562 T1070 T1189 T1195 T1543 T1055
MC Afeee Po Syslog Ama
Defense Evasion
T1562 T1070
MC Afeee Po Syslog Ama
Initial Access
T1566
MC Afeee Po Syslog Ama
Defense Evasion
T1562 T1070
MC Afeee Po Syslog Ama
Initial Access Privilege Escalation Defense Evasion
T1562 T1070 T1068 T1189 T1195
MC Afeee Po Syslog Ama
Defense Evasion
T1562 T1070
MC Afeee Po Syslog Ama
Defense Evasion
T1562 T1070
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Windows Firewall
Command and Control
T1071
Okta Sso Okta Ssov2
Credential Access
T1621
Azure Active Directory Behavior Analytics
Initial Access
T1078
Azure Active Directory
Credential Access
T1110
Cef Ama Palo Alto Networks Palo Alto Networks Ama
Execution
T1204
Microsoft Threat Protection
Initial Access
T1190
Security Events Windows Forwarded Events Windows Security Events
Collection
T1005
Security Events Windows Forwarded Events Windows Security Events
Collection
T1005
Azure Activity
Defense Evasion
T1578
Azure Activity
Defense Evasion
T1578
Azure Activity
Credential Access Defense Evasion
T1528 T1550
Security Events Windows Security Events
Discovery
T1012
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Defense Evasion
T1036
Azure Active Directory
Persistence Impact
T1098 T1078
Azure Active Directory
Defense Evasion
T1036
Security Events Windows Forwarded Events Windows Security Events
Execution
T1059
Security Events Windows Forwarded Events Windows Security Events
Persistence
T1547
Mimecast Audit API
Discovery Initial Access Credential Access
T1110
Mimecast Audit API
Discovery Initial Access Credential Access
T1110
Mimecast Siemapi
Exfiltration
T1030
Mimecast Segapi
Exfiltration
T1030
Mimecast Siemapi
Exfiltration
T1030
Mimecast Segapi
Exfiltration
T1030
Mimecast Siemapi
Collection Exfiltration Discovery Initial Access Execution
T1114 T1566 T0865
Mimecast Segapi
Collection Exfiltration Discovery Initial Access Execution
T1114 T1566 T0865
Mimecast Siemapi
Execution
T1053
Mimecast Segapi
Execution
T1053
Mimecast Segapi
Discovery Lateral Movement Collection
T1114
Mimecast Siemapi
Discovery Lateral Movement Collection
T1114
Mimecast Siemapi
Lateral Movement Persistence Exfiltration
T1534 T1546
Mimecast Segapi
Lateral Movement Persistence Exfiltration
T1534 T1546
Mimecast Segapi
Discovery
T1083
Mimecast Siemapi
Discovery
T1083
Mimecast Segapi
Initial Access Discovery Execution
T1566
Mimecast Siemapi
Initial Access Discovery Execution
T1566
Mimecast Siemapi
Execution
T1053
Mimecast Segapi
Execution
T1053
Mimecast Ttpapi
Initial Access Discovery
T0865
Mimecast Ttpapi
Initial Access Discovery
T0865
Mimecast Ttpapi
Exfiltration Collection Discovery
T1114
Mimecast Ttpapi
Exfiltration Collection Discovery
T1114
Mimecast Ttpapi
Initial Access Discovery
T0865
Mimecast Ttpapi
Initial Access Discovery
T0865
Impact Defense Evasion
T1499 T1564
Security Events
Persistence
T1546
Azure Active Directory
Credential Access Persistence Privilege Escalation
T1555 T1098
Microsoft Threat Protection
Defense Evasion
T1562
Aws Azure Active Directory
Credential Access Persistence
T1098 T1556
Azure Active Directory
Impact
T1531
Credential Access Discovery
T1110 T1212
Azure Active Directory Office365 Security Events Syslog Windows Forwarded Events Windows Security Events
Initial Access Credential Access
T1078 T1110
Security Events Windows Forwarded Events Windows Security Events
Lateral Movement
T1021
Azure Firewall
Exfiltration Command and Control
T1041 T1071
Office365
Impact
T1485 T1489
Office365
Collection Exfiltration
T1114 T1020
Office365
Collection Exfiltration
T1114 T1020
Netclean Pro Active Incidents
Discovery
T1083
Netskope Data Connector
Execution
T1204
Security Events Trend Micro Windows Forwarded Events Windows Security Events
Execution
T1204
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Asa Ama Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Reconnaissance Discovery
T1590 T1046
Prancer Log Data
Reconnaissance
T1595
Azure Active Directory
Defense Evasion
T1550
Azure Activity
Execution
T1059
Azure Active Directory
Initial Access Credential Access
T1078 T1110
Okta Sso Okta Ssov2
Initial Access Persistence
T1078 T1556
Authomize
Initial Access Privilege Escalation
T1078
Security Events Windows Security Events
Execution Lateral Movement
T1072 T1570
Security Events
Execution Lateral Movement
T1072 T1570
Office365
Command and Control Lateral Movement
T1105 T1570
Azure Active Directory
Persistence
T1098
Qualys Vulnerability Management
Initial Access
T1190
Azure Active Directory
Resource Development
T1585
Authomize
Initial Access
T1078
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Azure Active Directory
Persistence
T1078
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Aws Azure Monitor( Iis) Office365
Initial Access Command and Control Execution
T1189 T1071 T1203
Custom Logs Ama Nginxhttpserver
Initial Access
T1190 T1133
Custom Logs Ama Nginxhttpserver
Impact
T1499
Custom Logs Ama Nginxhttpserver
Initial Access
T1190 T1133
Custom Logs Ama Nginxhttpserver
Initial Access
T1190 T1133
Custom Logs Ama Nginxhttpserver
Impact Initial Access
T1498 T1190 T1133
Custom Logs Ama Nginxhttpserver
Initial Access
T1190 T1133
Custom Logs Ama Nginxhttpserver
Initial Access
T1190 T1133
Custom Logs Ama Nginxhttpserver
Initial Access
T1190 T1133
Custom Logs Ama Nginxhttpserver
Initial Access
T1189
Custom Logs Ama Nginxhttpserver
Initial Access
T1190
Command and Control
T1572 T1090 T1102
Io T
Inhibit Response Function
T0881
Security Events Windows Security Events
Credential Access
T1003
Senserva Pro
Initial Access
T1078
Azure Active Directory
Persistence
T1098
Security Events Windows Security Events
Execution Defense Evasion
T1059 T1027 T1140
Azure Activity
Defense Evasion
T1578
Azure Active Directory
Defense Evasion
T1550
Aws Awss3
Defense Evasion Privilege Escalation Persistence Initial Access
T1078
Office365
Persistence Defense Evasion
T1098 T1078
Azure Activity
Defense Evasion
T1578
Azure Active Directory
Credential Access Persistence Privilege Escalation
T1555 T1098
Office365
Collection Exfiltration
T1114 T1020
Azure Active Directory
Defense Evasion
T1550
Azure Active Directory
Persistence
T1078
Azure Active Directory
Privilege Escalation
T1078
Security Events Windows Security Events
Execution Defense Evasion
T1059 T1027 T1140
Security Events Windows Security Events
Defense Evasion
T1070
Azure Key Vault
Impact
T1485
Syslog Syslog Ama
Command and Control
T1102
Azure Active Directory
Persistence Privilege Escalation
T1098 T1078
Oracle Cloud Infrastructure Logs Connector
Discovery
T1580
Oracle Cloud Infrastructure Logs Connector
Defense Evasion
T1070
Oracle Cloud Infrastructure Logs Connector
Initial Access
T1190
Oracle Cloud Infrastructure Logs Connector
Discovery
T1069
Oracle Cloud Infrastructure Logs Connector
Discovery
T1069
Oracle Cloud Infrastructure Logs Connector
Impact
T1496
Oracle Cloud Infrastructure Logs Connector
Impact
T1529
Oracle Cloud Infrastructure Logs Connector
Reconnaissance
T1595
Oracle Cloud Infrastructure Logs Connector
Reconnaissance
T1595
Oracle Cloud Infrastructure Logs Connector
Initial Access
T1190
Microsoft Threat Protection
Execution Collection Command and Control
T1059 T1105 T1203
Microsoft Threat Protection
Initial Access
T1566
Office365
Persistence Defense Evasion
T1098 T1562
Office365
Exfiltration
T1020
Office365
Exfiltration
T1020
Okta Sso Okta Ssov2
Initial Access
T1566
Azure SQL
Initial Access
T1190
Custom Logs Ama Oracle Web Logic Server
Initial Access
T1190 T1133
Custom Logs Ama Oracle Web Logic Server
Initial Access
T1190 T1133
Custom Logs Ama Oracle Web Logic Server
Initial Access
T1190 T1133
Custom Logs Ama Oracle Web Logic Server
Impact Initial Access
T1498 T1190 T1133
Custom Logs Ama Oracle Web Logic Server
Initial Access
T1190 T1133
Custom Logs Ama Oracle Web Logic Server
Initial Access
T1190
Custom Logs Ama Oracle Web Logic Server
Initial Access
T1190 T1133
Custom Logs Ama Oracle Web Logic Server
Initial Access
T1190 T1133
Custom Logs Ama Oracle Web Logic Server
Initial Access Exfiltration
T1190 T1133 T1048
Custom Logs Ama Oracle Web Logic Server
Initial Access
T1189
Microsoft Threat Protection
Lateral Movement Privilege Escalation
T1210 T1611
Oracle Database Audit Syslog Ama
Initial Access Collection Exfiltration
T1190 T1133 T1078 T1119 T1029
Oracle Database Audit Syslog Ama
Initial Access
T1078
Oracle Database Audit Syslog Ama
Impact
T1485
Oracle Database Audit Syslog Ama
Initial Access Persistence
T1078
Oracle Database Audit Syslog Ama
Collection
T1005
Oracle Database Audit Syslog Ama
Impact
T1529
Oracle Database Audit Syslog Ama
Initial Access
T1190
Oracle Database Audit Syslog Ama
Collection
T1119
Oracle Database Audit Syslog Ama
Initial Access Persistence
T1078
Oracle Database Audit Syslog Ama
Initial Access
T1078
Azure SQL
Initial Access
T1190
Prancer Log Data
Reconnaissance
T1595
Cef Ama Palo Alto Networks Palo Alto Networks Ama
Discovery
T1046
Cloud Ngfw by Pan
Command and Control
T1071 T1571
Cef Ama Palo Alto Networks Palo Alto Networks Ama
Command and Control
T1071 T1571
Palo Alto Networks Cortex
Defense Evasion
T1562
Palo Alto Prisma Cloud
Initial Access
T1078
Palo Alto Prisma Cloud
Initial Access
T1078
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Initial Access
T1078
Palo Alto Prisma Cloud
Initial Access
T1078
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Credential Access
T1110
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Initial Access
T1133
Cef Ama Palo Alto Networks Palo Alto Networks Ama
Discovery Exfiltration Command and Control
T1046 T1030 T1071
Palo Alto Networks Cortex
Defense Evasion
T1562
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Reconnaissance
T1595
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Cef Ama Palo Alto Cdl Palo Alto Cdlama
Initial Access
T1190 T1133
Authomize
Credential Access Initial Access
T1555 T1040 T1552
Azure Active Directory
Credential Access
T1110
Azure Active Directory
Credential Access
T1110
Azure Active Directory
Credential Access
T1110
Microsoft Threat Protection
Credential Access
T1110
Microsoft Threat Protection
Execution
T1203
Cbspolling ID Azure Functions
Initial Access Reconnaissance
Check Point Fortinet Office Atp Palo Alto Networks Zscaler
Initial Access
T1566
Azure Active Directory
Persistence
T1078
Cef Ama Ping Federate Ping Federate Ama
Credential Access
T1110
Cef Ama Ping Federate Ping Federate Ama
Initial Access Persistence Privilege Escalation
T1078 T1098 T1134
Cef Ama Ping Federate Ping Federate Ama
Initial Access
T1078
Cef Ama Ping Federate Ping Federate Ama
Initial Access
T1078
Cef Ama Ping Federate Ping Federate Ama
Initial Access Persistence
T1078 T1136
Cef Ama Ping Federate Ping Federate Ama
Initial Access
T1190
Cef Ama Ping Federate Ping Federate Ama
Initial Access
T1078
Cef Ama Ping Federate Ping Federate Ama
Initial Access
T1190
Cef Ama Ping Federate Ping Federate Ama
Initial Access
T1078
Cef Ama Ping Federate Ping Federate Ama
Initial Access
T1078
Cef Ama Ping Federate Ping Federate Ama
Initial Access
T1078
Azure Firewall
Discovery
T1046
Sophos Xgfirewall Syslog Ama
Discovery
T1046
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Asa Ama Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Discovery
T1046
Azure Firewall
Discovery
T1046
Azure Active Directory Zscaler
Initial Access Defense Evasion Credential Access
T1078 T1557 T1111
Barracuda Cef Check Point Cisco Asa F5 Fortinet Palo Alto Networks Zscaler
Command and Control
T1568
Aivectra Stream Awss3 Azure Monitor( Vminsights) Azure Nsg Check Point Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Initial Access Command and Control
T1566 T1102
Security Events
Privilege Escalation
T1134
Azure Active Directory
Persistence
T1098
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Asa Ama Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events Zscaler
Command and Control
T1071 T1571
Security Events Windows Forwarded Events Windows Security Events
Persistence
T1554
Microsoft Threat Protection
Persistence
T1554
Squid Proxy Zscaler
Command and Control
T1568
DNS
Command and Control
T1568 T1008
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Zscaler
Command and Control
T1568 T1008
Command and Control
T1568 T1008
Command and Control
T1568 T1008
Infoblox Nios Syslog Ama
Initial Access
T1200
Security Events Windows Security Events
Privilege Escalation
T1548
Privilege Escalation
T1548
Security Events Windows Forwarded Events Windows Security Events
Credential Access
T1558
Salesforce Service Cloud
Credential Access
T1110
Okta Sso Okta Ssov2
Credential Access
T1110
Microsoft Threat Protection
Execution Persistence Defense Evasion Impact
T1059 T1078 T1070 T1490
Security Events Windows Security Events
Defense Evasion Impact
T1485 T1036
Defense Evasion Impact
T1485 T1036
Security Events Windows Security Events
Command and Control
T1572
Security Events Windows Forwarded Events Windows Security Events
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Lateral Movement Persistence Privilege Escalation
T1548 T1134 T1134 T1134 T1087 T1087 T1557 T1071 T1560 T1547 T1547 T1547 T1217 T1115 T1059 T1059 T1059 T1136 T1136 T1543 T1555 T1484 T1482 T1114 T1573 T1546 T1041 T1567 T1567 T1068 T1210 T1083 T1615 T1574 T1574 T1574 T1574 T1574 T1070 T1105 T1056 T1056 T1106 T1046 T1135 T1040 T1027 T1003 T1057 T1055 T1021 T1021 T1053 T1113 T1518 T1558 T1558 T1082 T1016 T1049 T1569 T1127 T1552 T1552 T1550 T1125 T1102 T1047
Microsoft Threat Protection Security Events
Execution
T1203
Microsoft Defender Threat Intelligence Microsoft Threat Protection
Command and Control
T1071
Microsoft Defender Threat Intelligence Microsoft Threat Protection
Initial Access
T1566
Microsoft Defender Threat Intelligence Microsoft Threat Protection
Command and Control
T1071
Microsoft Defender Threat Intelligence Microsoft Threat Protection
Command and Control
T1071
Microsoft Defender Threat Intelligence Microsoft Threat Protection
Command and Control
T1071
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Azure Active Directory Behavior Analytics
Privilege Escalation
T1078
Azure Active Directory Behavior Analytics
Initial Access
T1078
Authomize
Discovery Impact
T1580
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory Behavior Analytics
Defense Evasion
T1078
Microsoft Threat Protection
Discovery
T1016 T1018 T1069 T1087 T1482
Cisco Secure Endpoint Crowd Strike Falcon Endpoint Protection Microsoft Threat Protection Sentinel One Trend Micro Apex One Trend Micro Apex One Ama Vmware Carbon Black
Execution Defense Evasion
T1059 T1027
Security Events Windows Forwarded Events Windows Security Events
Execution Defense Evasion
T1059 T1027 T1140
Security Events Windows Security Events
Execution
T1059
Windows Forwarded Events
Exfiltration
T1020
Windows Forwarded Events
Exfiltration
T1020
Proofpoint Pod
Initial Access
T1078
Proofpoint Pod Threat Intelligence Threat Intelligence Taxii
Exfiltration Initial Access
T1078 T1567
Proofpoint Pod Threat Intelligence Threat Intelligence Taxii
Exfiltration Initial Access
T1078 T1567
Proofpoint Pod
Initial Access
T1566
Proofpoint Pod
Exfiltration
T1567
Proofpoint Pod
Exfiltration
T1567
Proofpoint Pod
Exfiltration
T1567
Proofpoint Pod
Initial Access
T1078
Proofpoint Pod
Initial Access
T1566
Proofpoint Pod
Commandand Control
T1573
Pulse Connect Secure
Initial Access
T1190
Pulse Connect Secure Syslog Ama
Credential Access
T1110
Pulse Connect Secure Syslog Ama
Credential Access
T1110
Microsoft Threat Protection
Defense Evasion
T1070
Microsoft Threat Protection
Defense Evasion Discovery Execution
T1140 T1010 T1059
Radiflow Isid
Initial Access Privilege Escalation Lateral Movement
T0819 T0866 T0890
Radiflow Isid
Discovery
T0840 T0846 T0888
Radiflow Isid
Initial Access
T1133 T0848
Radiflow Isid
Privilege Escalation Execution Command and Control Exfiltration Lateral Movement Impair Process Control Inhibit Response Function Initial Access
Radiflow Isid
Lateral Movement Impair Process Control Execution Collection Persistence
T0886 T0855 T0858 T0845 T0889 T0843
Radiflow Isid
Defense Evasion Inhibit Response Function
T0851
Radiflow Isid
Execution Lateral Movement Inhibit Response Function Impair Process Control
T0858 T0843 T0816 T0857 T0836 T0855
Radiflow Isid
Initial Access Impact
T0822 T0883 T0882
Nasuni Edge Appliance Syslog Ama
Impact
T1486
Nasuni Edge Appliance Syslog Ama
Impact
T1486
Office365
Persistence Collection
T1098 T1114
Azure Active Directory
Persistence Privilege Escalation
T1136 T1068
Microsoft Threat Protection
Persistence
T1543 T1543
Security Events Windows Forwarded Events Windows Security Events
Lateral Movement
T1021
Azure Activity
Credential Access Persistence
T1003 T1098
Security Events Windows Forwarded Events Windows Security Events
Lateral Movement
T1021
Threat Intelligence Upload Indicators API
Initial Access Command and Control
T1566 T1568
Threat Intelligence Upload Indicators API
Initial Access Execution Persistence
T1189 T1059 T1554
Threat Intelligence Upload Indicators API
Exfiltration Command and Control
T1041 T1568
Threat Intelligence Upload Indicators API
Persistence Privilege Escalation Defense Evasion
T1098 T1078
Red Canary Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Authomize
Privilege Escalation
T1078
Prancer Log Data
Reconnaissance
T1595
Security Events Windows Security Events
Persistence
T1546
Security Events Windows Security Events
Persistence
T1546
Microsoft Threat Protection
Defense Evasion
T1218 T1218
Microsoft Threat Protection
Defense Evasion
T1218 T1218
Microsoft Threat Protection
Lateral Movement
T1021
Microsoft Threat Protection
Lateral Movement
T1570
Microsoft Threat Protection
Defense Evasion
T1036
Cef Ama Zscaler Zscaler Ama
Command and Control
T1102 T1071
Azure SQL
Exfiltration
T1537 T1567
Azure Active Directory Check Point Fortinet Palo Alto Networks Zscaler
Command and Control
T1071
Check Point Fortinet Palo Alto Networks Zscaler
Exfiltration Command and Control
T1041 T1071
Sail Point Identity Now
Initial Access Collection
T1133 T1005
Sail Point Identity Now
Initial Access
T1133
Sail Point Identity Now
Initial Access
T1133
Sail Point Identity Now
Initial Access
T1133
Sail Point Identity Now
Initial Access
T1133
Sail Point Identity Now
Initial Access
T1133
Security Events Windows Security Events
Defense Evasion
T1562
Security Events Windows Security Events
Impact
T1485
Security Events Windows Forwarded Events Windows Security Events
Defense Evasion
T1070
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Defense Evasion
T1562
Custom Logs Ama Security Bridge Sap
Initial Access
T1189
Security Events Windows Security Events
Credential Access
T1110
Semperis Dsp
Initial Access Credential Access
T1078 T1110
Semperis Dsp
Credential Access
T1558
Semperis Dsp
Defense Evasion
T1207
Semperis Dsp
Initial Access Credential Access Resource Development
T1133 T1110 T1584
Semperis Dsp
Privilege Escalation Persistence
T1548 T1098
Semperis Dsp
Privilege Escalation Persistence
T1098
Semperis Dsp
Privilege Escalation Defense Evasion
T1134
Semperis Dsp
Privilege Escalation
T1068
Senserva Pro
Impact
T1529 T1485
Azure Key Vault
Impact
T1485
Microsoft Azure Purview
Discovery
T1087
Microsoft Azure Purview
Discovery
T1087
Sentinel One
Initial Access Privilege Escalation
T1078
Sentinel One
Defense Evasion
T1070
Sentinel One
Initial Access
T1190
Sentinel One
Defense Evasion
T1070
Sentinel One
Defense Evasion
T1070
Sentinel One
Initial Access
T1190
Sentinel One
Privilege Escalation
T1078
Sentinel One
Defense Evasion
T1070
Sentinel One
Defense Evasion
T1070
Sentinel One
Initial Access Lateral Movement
T1190 T1210
Sentinel One
Credential Access
T1555
Esi Exchange Admin Audit Log Events
Exfiltration Persistence Collection
T1020 T1098 T1114
Microsoft Threat Protection
Lateral Movement
T1210
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Initial Access
T1078
Security Events
Privilege Escalation
T1134
Senserva Pro
Initial Access
T1078
Azure Firewall
Discovery Lateral Movement Command and Control
T1046 T1071 T1210
Syslog Syslog Ama
Exfiltration
T1020
Syslog Syslog Ama
Exfiltration
T1020
Microsoft Threat Protection
Impact
T1490
Office365
Exfiltration
T1030
Office365
Exfiltration
T1030
Azure Active Directory Behavior Analytics
Initial Access Persistence
T1078 T1098
Initial Access Persistence
T1078 T1098
Security Events Windows Forwarded Events Windows Security Events
Initial Access
T1190
Azure Monitor( Iis)
Initial Access
T1190
Silverfort Ama
Privilege Escalation
T1068
Silverfort Ama
Initial Access
T1190
Silverfort Ama
Privilege Escalation
T1068 T1548
Silverfort Ama
Credential Access
T1110
Prancer Log Data
Reconnaissance
T1595
Slack Audit API
Initial Access
T1133
Slack Audit API
Exfiltration
T1567
Slack Audit API
Credential Access
T1110
Slack Audit API
Exfiltration
T1048
Slack Audit API
Initial Access
T1189
Slack Audit API
Command and Control
T1071
Slack Audit API
Initial Access
T1078
Slack Audit API
Initial Access Persistence Privilege Escalation
T1078
Slack Audit API
Persistence Privilege Escalation
T1098 T1078
Microsoft Threat Protection
Lateral Movement
T1021
Snowflake
Discovery
T1518 T1082
Snowflake
Initial Access
T1078
Snowflake
Initial Access
T1078
Snowflake
Privilege Escalation
T1078
Microsoft Defender Advanced Threat Protection Microsoft Threat Protection
Initial Access
T1195
Security Events Windows Forwarded Events Windows Security Events
Defense Evasion Privilege Escalation
T1055
Cef Cef Ama Sonic Wall Firewall
Initial Access Execution Persistence Credential Access Discovery Lateral Movement Collection Exfiltration Impact
T1190 T1133 T1059 T1110 T1003 T1087 T1018 T1021 T1005 T1048 T1041 T1011 T1567 T1490
Cef Cef Ama Sonic Wall Firewall
Execution
T1204
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Sonrai Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
T1566 T1059 T1547 T1548 T1562 T1003 T1087 T1021 T1119 T1071 T1041 T1499
Hvpolling ID Azure Functions
Initial Access Reconnaissance
Hvpolling ID Azure Functions
Initial Access Reconnaissance
Syslog Syslog Ama
Command and Control
T1090 T1008
Syslog Syslog Ama
Command and Control
T1102
Syslog Syslog Ama
Credential Access
T1110
Authomize
Initial Access
T1078
Authomize
Privilege Escalation Persistence
T1098
Senserva Pro
Initial Access
T1566
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Microsoft Threat Protection Palo Alto Networks
Initial Access
T1566
Security Events Windows Security Events
Defense Evasion
T1562
Microsoft Threat Protection
Defense Evasion
T1562
Prancer Log Data
Reconnaissance
T1595
Cbspolling ID Azure Functions
Reconnaissance Initial Access
T1590 T1566
Prancer Log Data
Reconnaissance
T1595
Hvpolling ID Azure Functions
Initial Access
T1189
Azure Activity
Impact
T1496
Aws Azure Active Directory Identity Protection Behavior Analytics Microsoft Defender Advanced Threat Protection Microsoft Threat Protection
Initial Access Credential Access
T1110 T1078
Azure Active Directory Behavior Analytics
Credential Access Initial Access
T1110 T1078
Microsoft Threat Protection
Execution Persistence Initial Access
T1195 T1059 T1546
Execution Persistence Initial Access
T1195 T1059 T1546
Microsoft Threat Protection
Execution Persistence Initial Access
T1195 T1059 T1546
Microsoft Threat Protection
Execution Persistence
Execution Persistence
T1059 T1543
Microsoft Threat Protection
Persistence
T1554
Azure Monitor( Iis)
Persistence Command and Control
T1505 T1071
Azure Active Directory
Credential Access
T1528
Azure Active Directory
Credential Access Defense Evasion
T1528 T1550
Azure Active Directory
Credential Access Defense Evasion
T1528 T1550
Aws
Reconnaissance
T1595 T1592 T1589 T1589 T1590 T1591 T1596
Aws Azure Active Directory Identity Protection Behavior Analytics Microsoft Defender Advanced Threat Protection Microsoft Threat Protection Office Atp
Initial Access Credential Access
T1078
Azure Active Directory
Credential Access
T1528
Azure Activity Behavior Analytics
Persistence Privilege Escalation
T1098 T1548
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Privilege Escalation
T1078
Cbspolling ID Azure Functions
Resource Development
T1587 T1588
Cbspolling ID Azure Functions
Resource Development
T1587 T1588
Azure Active Directory Behavior Analytics
Privilege Escalation
T1078
Microsoft Threat Protection
Execution Defense Evasion
T1559 T1055
Azure Activity
Impact
T1496
Microsoft Threat Protection
Initial Access
T1566
Microsoft Threat Protection
Execution
T1059
Microsoft Threat Protection
Execution
T1204
Azure Activity
Impact
T1496
Azure Active Directory
Credential Access Privilege Escalation Initial Access
T1078 T1528
Behavior Analytics
Initial Access
T1078
Azure Active Directory Behavior Analytics
Initial Access Defense Evasion
T1078 T1556
Azure Active Directory Identity Protection Behavior Analytics Gcpaudit Logs Definition Microsoft Cloud App Security Microsoft Defender Advanced Threat Protection Microsoft Threat Protection
Initial Access Execution Discovery
T1078 T1106 T1526
Azure SQL
Initial Access
T1190
Microsoft Threat Protection
Execution Persistence Defense Evasion
T1543 T1059 T1027
Tenable Ad
Credential Access
T1110
Tenable Ad
Defense Evasion
T1207
Tenable Ad
Credential Access
T1003
Tenable Ad
Credential Access
T1558
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1003
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Theom
Collection
T1560 T1530
Theom
Collection
T1213 T1530
Theom
Credential Access
T1552
Theom
Collection
T1213 T1530
Theom
Collection
T1213 T1530
Theom
Collection
T1213 T1530
Theom
Collection
T1213 T1530
Theom
Collection
T1560 T1530
Theom
Collection
T1213 T1530
Theom
Collection
T1213 T1530
Theom
Collection Privilege Escalation
T1560 T1530 T1078
Theom
Collection
T1560 T1530
Theom
Collection Privilege Escalation
T1560 T1530 T1078
Theom
Collection
T1213 T1530
Theom
Collection Command and Control Credential Access Defense Evasion Discovery Exfiltration Impact Reconnaissance
T1592 T1589 T1070 T1552 T1619 T1119 T1560 T1530 T1213 T1001 T1041 T1537 T1485 T1486 T1565
Theom
Collection Command and Control Credential Access Defense Evasion Discovery Exfiltration Impact Reconnaissance
T1592 T1589 T1070 T1552 T1619 T1119 T1560 T1530 T1213 T1001 T1041 T1537 T1485 T1486 T1565
Theom
Collection Command and Control Credential Access Defense Evasion Discovery Exfiltration Impact Reconnaissance
T1592 T1589 T1070 T1552 T1619 T1119 T1560 T1530 T1213 T1001 T1041 T1537 T1485 T1486 T1565
Theom
Collection Command and Control Credential Access Defense Evasion Discovery Exfiltration Impact Reconnaissance
T1592 T1589 T1070 T1552 T1619 T1119 T1560 T1530 T1213 T1001 T1041 T1537 T1485 T1486 T1565
Theom
Collection Command and Control Credential Access Defense Evasion Discovery Exfiltration Impact Reconnaissance
T1592 T1589 T1070 T1552 T1619 T1119 T1560 T1530 T1213 T1001 T1041 T1537 T1485 T1486 T1565
Senserva Pro
Exfiltration
T1020
Asim DNS Activity Logs DNS Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Office365
Collection Exfiltration
T1114 T1020
Azure Activity
Impact
T1485
Azure Active Directory
Impact
T1531
Azure Active Directory
Persistence Privilege Escalation
T1098 T1078
Azure Monitor( Vminsights) Cisco Asa Cisco Asa Ama Palo Alto Networks
Exfiltration
T1030
Azure Active Directory
Persistence
T1078
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Active Directory Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Threat Intelligence
Command and Control
T1071
Microsoft Defender Threat Intelligence Office365 Threat Intelligence
Command and Control
T1071
Eset Smc
Execution Credential Access Privilege Escalation
T1204 T1212 T1548
Esetprotect Syslog Ama
Execution
T1204
Microsoft Defender Threat Intelligence Microsoft Threat Protection Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Defender Threat Intelligence Nxlog DNS Logs Threat Intelligence Threat Intelligence Taxii Zscaler
Command and Control
T1071
DNS Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Initial Access
T1566
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Initial Access
T1566
Microsoft Defender Threat Intelligence Palo Alto Networks Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Security Center Microsoft Cloud App Security Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Syslog Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Squid Proxy Threat Intelligence Threat Intelligence Taxii Zscaler
Command and Control
T1071
Azure Activity Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Initial Access
T1566
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Initial Access
T1566
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Initial Access
T1566
Microsoft Defender Threat Intelligence Palo Alto Networks Threat Intelligence Threat Intelligence Taxii
Initial Access
T1566
Azure Security Center Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Initial Access
T1566
Microsoft Defender Threat Intelligence Security Events Threat Intelligence Threat Intelligence Taxii Windows Forwarded Events Windows Security Events
Initial Access
T1566
Azure Active Directory Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Initial Access
T1566
Microsoft Defender Threat Intelligence Palo Alto Networks Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Microsoft Threat Protection Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Security Events Threat Intelligence Threat Intelligence Taxii Windows Forwarded Events Windows Security Events
Command and Control
T1071
Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Aws Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Key Vault Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure SQL Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Activity Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Firewall Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Cef Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Microsoft Threat Protection Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Defender Threat Intelligence Nxlog DNS Logs Threat Intelligence Threat Intelligence Taxii Zscaler
Command and Control
T1071
DNS Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Cisco Duo Security Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Last Pass Threat Intelligence
Impact
T1485
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Meraki Corelight Fortinet Microsoft Defender Threat Intelligence Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Threat Intelligence Taxii Windows Forwarded Events Zscaler
Command and Control
T1071
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Active Directory Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Monitor( Vminsights) Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Monitor( Iis) Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Squid Proxy Threat Intelligence Threat Intelligence Taxii Zscaler
Command and Control
T1071
Azure Active Directory Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Microsoft Threat Protection Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Active Directory Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Palo Alto Networks Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Azure Security Center Microsoft Cloud App Security Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Syslog Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Microsoft Defender Threat Intelligence Microsoft Threat Protection Threat Intelligence Threat Intelligence Taxii
Command and Control
T1071
Tenable Ie
Credential Access
T1110
Tenable Ie
Defense Evasion
T1207
Tenable Ie
Credential Access
T1003
Tenable Ie
Credential Access
T1558
Tenable Ie
Credential Access
T1110
Tenable Ie
Credential Access
T1110
Tenable Ie
Credential Access
T1003
Tenable Ie
Credential Access
T1110
Tenable Ie
Credential Access
T1110
Tenable Ie
Credential Access
T1110
Tenable Ie
Credential Access
T1110
Tenable Ie
Credential Access
T1110
Barracuda Cef Check Point Cisco Asa F5 Fortinet Palo Alto Networks
Exfiltration
T1030
Azure Monitor( Vminsights) Cisco Asa Palo Alto Networks
Exfiltration
T1030
Hvpolling ID Azure Functions
Credential Access Defense Evasion Persistence
T1556
Hvpolling ID Azure Functions
Credential Access Lateral Movement Defense Evasion Persistence
T1556 T1210 T1212
Hvpolling ID Azure Functions
Credential Access Lateral Movement Defense Evasion Persistence
T1556 T1210 T1212
Hvpolling ID Azure Functions
Credential Access Lateral Movement Defense Evasion Persistence
T1556 T1210 T1212
Hvpolling ID Azure Functions
Credential Access Lateral Movement Defense Evasion Persistence
T1556 T1210 T1212
Hvpolling ID Azure Functions
Credential Access Lateral Movement Defense Evasion Persistence
T1556 T1210 T1212
Hvpolling ID Azure Functions
Credential Access Lateral Movement Defense Evasion Persistence
T1556 T1210 T1212
Apache Tomcat Custom Logs Ama
Initial Access
T1190 T1133
Apache Tomcat Custom Logs Ama
Initial Access
T1190 T1133
Apache Tomcat Custom Logs Ama
Initial Access
T1190 T1133
Apache Tomcat Custom Logs Ama
Initial Access Impact
T1190 T1133 T1499
Apache Tomcat Custom Logs Ama
Impact Initial Access
T1498 T1190 T1133
Apache Tomcat Custom Logs Ama
Initial Access
T1190 T1133
Apache Tomcat Custom Logs Ama
Initial Access
T1190 T1133
Apache Tomcat Custom Logs Ama
Initial Access
T1189
Apache Tomcat Custom Logs Ama
Impact Initial Access
T1498 T1190 T1133
Apache Tomcat Custom Logs Ama
Initial Access
T1190
Trend Micro Cas
Exfiltration
T1048
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Impact
T1486
Trend Micro Cas
Impact
T1486
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Defense Evasion
T1562
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Initial Access
T1566
Credential Access
T1528 T1555
Microsoft Threat Protection
Defense Evasion
T1127
Custom Logs Ama Ubiquiti Unifi
Exfiltration Command and Control
T1071 T1571 T1572
Custom Logs Ama Ubiquiti Unifi
Command and Control Exfiltration
T1572 T1041
Custom Logs Ama Ubiquiti Unifi
Exfiltration Command and Control
T1041 T1572
Custom Logs Ama Ubiquiti Unifi
Command and Control
T1071 T1095 T1571
Custom Logs Ama Ubiquiti Unifi
Initial Access
T1133
Custom Logs Ama Ubiquiti Unifi
Initial Access
T1133
Custom Logs Ama Ubiquiti Unifi
Initial Access
T1133
Custom Logs Ama Ubiquiti Unifi
Command and Control
T1090 T1572
Custom Logs Ama Ubiquiti Unifi
Exfiltration Command and Control
T1048 T1071
Custom Logs Ama Ubiquiti Unifi
Command and Control
T1573
Awss3 Azure Active Directory
Credential Access Exfiltration Discovery
T1557 T1110 T1110 T1110 T1212 T1048 T1087 T1580
Authomize
Initial Access Privilege Escalation
T1078 T1068
Microsoft Threat Protection Security Events
Persistence
T1136
Microsoft Threat Protection
Impact
T1485
Azure Active Directory
Persistence Privilege Escalation
T1078
Symantec Proxy Sg Syslog Ama
Initial Access Command and Control
T1566 T1071
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Azure Active Directory
Persistence
T1136
Azure Active Directory
Persistence
T1136
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Azure Active Directory Behavior Analytics
Initial Access
T1078
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Persistence Privilege Escalation
T1098 T1078
Aws Azure Active Directory Azure Monitor( Iis) Office365 Squid Proxy Waf Zscaler
Initial Access
T1190
Defense Evasion Impact
T1578 T1531
Azure Active Directory
Persistence
T1078
Authomize
Initial Access
T1078
Aws Azure Active Directory Identity Protection
Privilege Escalation
T1134
Initial Access Privilege Escalation
T1078
Okta Sso Okta Ssov2
Initial Access
T1078
Okta Sso Okta Ssov2
Privilege Escalation
T1134 T1134
Salesforce Service Cloud
Initial Access
T1078
Azure Active Directory
Persistence
T1098
Authomize
Initial Access
T1078
Senserva Pro
Initial Access
T1078
Collection Exfiltration
T1530 T1213 T1020
Cef Ama V Armour Ac V Armour Acama
Discovery Lateral Movement
T1135 T1570
Prancer Log Data
Reconnaissance
T1595
Custom Logs Ama V Center
Privilege Escalation
T1078
Aivectra Detect Aivectra Detect Ama Cef Ama
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
T1003 T1087 T1021 T1119 T1071 T1041 T1499
Aivectra Detect Aivectra Detect Ama Cef Ama
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
T1003 T1087 T1021 T1119 T1071 T1041 T1499
Aivectra Detect Aivectra Detect Ama Cef Ama
Lateral Movement Command and Control
T1021 T1071
Aivectra Detect Aivectra Detect Ama Cef Ama
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
T1003 T1087 T1021 T1119 T1071 T1041 T1499
Aivectra Detect Aivectra Detect Ama Cef Ama
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
T1003 T1087 T1021 T1119 T1071 T1041 T1499
Aivectra Detect Aivectra Detect Ama Cef Ama
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
T1003 T1087 T1021 T1119 T1071 T1041 T1499
Vectra Xdr
Persistence
T1546
Vectra Xdr
Persistence
T1546
Vectra Xdr
Persistence
T1546
Vectra Xdr
Persistence
T1546
Vectra Xdr
Persistence
T1546
Vectra Xdr
Persistence
T1546
Aivectra Detect Aivectra Detect Ama Cef Ama
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
T1003 T1087 T1021 T1119 T1071 T1041 T1499
Esi Exchange Admin Audit Log Events
Exfiltration Persistence Collection
T1020 T1098 T1114
Prancer Log Data
Reconnaissance
T1595
Prancer Log Data
Reconnaissance
T1595
Syslog Ama Vmware Esxi
Initial Access
T1190
Syslog Ama Vmware Esxi
Impact
T1529
Syslog Ama Vmware Esxi
Impact
T1529
Syslog Ama Vmware Esxi
Initial Access
T1078
Syslog Ama Vmware Esxi
Impact
T1529
Syslog Ama Vmware Esxi
Initial Access
T1078
Syslog Ama Vmware Esxi
Privilege Escalation
T1078
Syslog Ama Vmware Esxi
Initial Access Privilege Escalation
T1078
Syslog Ama Vmware Esxi
Initial Access Privilege Escalation
T1078
Syslog Ama Vmware Esxi
Impact
T1496
Syslog Ama Vmware Esxi
Impact
T1529
Vmware Sdwan
Lateral Movement
T1210
Vmware Sdwan
Lateral Movement
T1210
Vmware Sdwan
Impact Defense Evasion
T1498 T1599
Custom Logs Ama V Center
Initial Access Privilege Escalation
T1078
Cef Ama Votiro
Defense Evasion Discovery Impact
T1036 T1083 T1057 T1082 T1565 T1498 T0837
Cef Ama Votiro
Command and Control Defense Evasion Impact Initial Access
T0885 T1036 T1027 T1486 T1566
Cef Ama Ridge Bot Data Connector
Execution Initial Access Privilege Escalation
T1189 T1059 T1053 T1548
Initial Access Execution
T1190 T1203
Initial Access Execution
T1190 T1203
Security Events Windows Security Events
Credential Access
T1003
Eset Smc
Exfiltration Command and Control Initial Access
T1189 T1567 T1071
Esetprotect Syslog Ama
Exfiltration Command and Control Initial Access
T1041 T1071 T1189 T1566
Security Events Windows Security Events
Execution
T1059
Security Events Windows Security Events
Execution
T1059
Check Point Fortinet Microsoft Threat Protection Palo Alto Networks Zscaler
Exfiltration Command and Control
T1041 T1071
Azure Active Directory Identity Protection Azure Activity Behavior Analytics
Initial Access Impact
T1078 T1489
Zero Networks Segment Audit Function Zero Networks Segment Audit Native Poller
Defense Evasion
T1562
Zero Networks Segment Audit Function Zero Networks Segment Audit Native Poller
Credential Access
T1528
Zero Networks Segment Audit Function Zero Networks Segment Audit Native Poller
Lateral Movement
T1021
Zero Fox Alert Polling
Resource Development Initial Access
T1583 T1586 T1566
Zero Fox Alert Polling
Resource Development Initial Access
T1583 T1586 T1566
Zero Fox Alert Polling
Resource Development Initial Access
T1583 T1586 T1566
Zero Fox Alert Polling
Resource Development Initial Access
T1583 T1586 T1566
Microsoft Threat Protection Security Events Windows Security Events
Persistence
T1546
Credential Access Discovery
T1040
Custom Logs Ama Zscaler Private Access
Persistence
T1078
Custom Logs Ama Zscaler Private Access
Initial Access
T1190 T1133
Custom Logs Ama Zscaler Private Access
Initial Access
T1078 T1133
Custom Logs Ama Zscaler Private Access
Initial Access
T1078 T1133
Custom Logs Ama Zscaler Private Access
Initial Access
T1190 T1133
Custom Logs Ama Zscaler Private Access
Initial Access
T1078 T1133
Custom Logs Ama Zscaler Private Access
Persistence
T1078
Custom Logs Ama Zscaler Private Access
Initial Access
T1190 T1133
Custom Logs Ama Zscaler Private Access
Initial Access
T1078 T1133
Custom Logs Ama Zscaler Private Access
Initial Access
T1190 T1133