Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Defender Threat Intelligence Nxlog DNS Logs Threat Intelligence Threat Intelligence Taxii Zscaler
Impact
Microsoft Defender Threat Intelligence Squid Proxy Threat Intelligence Zscaler
Impact
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Defender Threat Intelligence Nxlog DNS Logs Threat Intelligence Threat Intelligence Taxii Zscaler
Impact
Microsoft Defender Threat Intelligence Squid Proxy Threat Intelligence Threat Intelligence Taxii Zscaler
Impact
Azure Firewall Cef Check Point Cisco Asa F5 Fortinet Microsoft Threat Protection Palo Alto Networks Security Events Windows Firewall Windows Forwarded Events Windows Security Events
Impact
T1496
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Palo Alto Networks Security Events
Persistence
T1137
Cisco Asa Microsoft Threat Protection Palo Alto Networks Security Events Windows Security Events
Impact
T1561
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Security Events Windows Firewall Windows Forwarded Events Windows Security Events
Persistence
T1546
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Security Events Windows Firewall
Impact
T1496
Microsoft Threat Protection Security Events
Execution
T1203
Azure Monitor( Vminsights) DNS Microsoft Threat Protection
Command and Control
T1071
Microsoft Threat Protection Security Events Windows Firewall
Execution
T1203
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Security Events Windows Firewall
Initial Access
T1190
Aws Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Cisco Asa Microsoft Threat Protection Office365 Palo Alto Networks Security Events
Impact
T1486
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Palo Alto Networks Zscaler
Command and Control Credential Access
Awss3 Azure Monitor( Iis) Azure Monitor( Wire Data) Cef Check Point Cisco Asa Cisco Umbrella Data Connector Corelight DNS F5 Fortinet Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Nxlog DNS Logs Palo Alto Networks Security Events Windows Firewall Windows Forwarded Events Zscaler
Initial Access
T1190
Cisco Asa Microsoft Threat Protection Palo Alto Networks Security Events
Impact
T1486
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Palo Alto Networks Squid Proxy Zscaler
Command and Control
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control Execution
T1071 T1204
Cisco Asa Palo Alto Networks Security Events
Command and Control Credential Access
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Palo Alto Networks Security Events Zscaler
Command and Control Credential Access
Office365
Initial Access Collection
T1133 T1114
Azure Firewall Azure Monitor( Vminsights) Cisco Asa DNS Fortinet Office Atp Palo Alto Networks Zscaler
Command and Control Initial Access
T1071 T1566
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Palo Alto Networks Security Events Squid Proxy Zscaler
Command and Control
T1071
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Office365 Palo Alto Networks Squid Proxy Zscaler
Command and Control
T1071
Aws Awss3 Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Azure Monitor( Vminsights) Azure Monitor( Wire Data) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Palo Alto Networks Squid Proxy Zscaler
Command and Control Credential Access
Aws Awss3 Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Security Events Squid Proxy Windows Forwarded Events Zscaler
Command and Control
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Squid Proxy Zscaler
Command and Control
T1102
Awss3 Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa Cisco Umbrella Data Connector Corelight DNS F5 Fortinet Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Security Events Squid Proxy Windows Firewall Windows Forwarded Events Zscaler
Command and Control Execution
T1102 T1204
Azure Monitor( Iis) Cef Check Point Cisco Asa F5 Fortinet Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Windows Security Events
Collection
T1005
Microsoft Threat Protection Security Events
Execution
T1203
Office365
Credential Access
T1110
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Initial Access
T1190
Azure Monitor( Vminsights)
Command and Control
T1102
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Threat Protection Nxlog DNS Logs Palo Alto Networks Zscaler
Command and Control
T1102
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Persistence
T1554
Cisco Asa Microsoft Threat Protection Palo Alto Networks Security Events
Persistence
T1053
Aws Awss3 Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Azure Monitor( Vminsights) Azure Monitor( Wire Data) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Microsoft Sysmon for Linux Microsoft Threat Protection Nxlog DNS Logs Office365 Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control
Squid Proxy Zscaler
Initial Access
Squid Proxy Zscaler
Commandand Control
Squid Proxy Zscaler
Commandand Control
Squid Proxy Zscaler
Commandand Control Defense Evasion
Security Events Windows Security Events
Discovery
T1012
Azure Firewall
Initial Access Exfiltration Command and Control
Azure Firewall
Defense Evasion Exfiltration Command and Control
Microsoft Threat Protection
Privilege Escalation Defense Evasion
T1134
Office365
Initial Access
T1566
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Persistence
T1136
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Persistence
T1078
Security Events Windows Forwarded Events Windows Security Events
Persistence
T1098
Security Events
Credential Access
T1552
Security Events Windows Security Events
Collection
T1005
Security Events Windows Security Events
Collection
T1005
Security Events Windows Security Events
Persistence
T1098
Azure Active Directory Behavior Analytics
Persistence
T1078
Security Events Windows Security Events
Collection
T1005
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Collection
T1005
Azure Active Directory
Privilege Escalation Persistence
T1098 T1078
Security Events
Persistence
T1078
Azure SQL
Impact
T1485 T1565 T1491
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Defense Evasion
T1207
Alsid for Ad
Credential Access
T1003
Alsid for Ad
Credential Access
T1558
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1003
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Alsid for Ad
Credential Access
T1110
Azure Active Directory Office365
Initial Access Persistence
T1199 T1136 T1078 T1098
Azure Active Directory
Initial Access
T1078
Azure Monitor( Iis)
Initial Access
T1190
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control Discovery Exfiltration Lateral Movement
T1095 T1071 T1046 T1030 T1210
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Initial Access
T1078
Apache HTTP Server
Initial Access Lateral Movement
T1190 T1133 T1210
Apache HTTP Server
Initial Access
T1190 T1133
Apache HTTP Server
Initial Access
T1190 T1133
Apache HTTP Server
Initial Access
T1190 T1133
Apache HTTP Server
Impact Initial Access
T1498 T1190 T1133
Apache HTTP Server
Initial Access
T1190 T1133
Apache HTTP Server
Initial Access Exfiltration
T1190 T1133 T1048
Apache HTTP Server
Impact Initial Access
T1498 T1190 T1133
Apache HTTP Server
Initial Access
T1189
Apache HTTP Server
Initial Access
T1190 T1133
Trend Micro Apex One
Initial Access
T1190
Trend Micro Apex One
Command and Control
T1071
Trend Micro Apex One
Initial Access
T1190 T1133
Trend Micro Apex One
Privilege Escalation
T1078
Trend Micro Apex One
Lateral Movement
T1021
Trend Micro Apex One
Initial Access
T1190
Trend Micro Apex One
Privilege Escalation Persistence
T1546
Trend Micro Apex One
Initial Access
T1190
Trend Micro Apex One
Execution
T1059
Trend Micro Apex One
Command and Control
T1102
42 Crunch API Protection
Credential Access Discovery
T1110 T1087
42 Crunch API Protection
Defense Evasion
42 Crunch API Protection
Reconnaissance Collection
42 Crunch API Protection
Exfiltration
42 Crunch API Protection
Reconnaissance
42 Crunch API Protection
Credential Access
42 Crunch API Protection
Reconnaissance Discovery
42 Crunch API Protection
Credential Access
T1110 T1555 T1187
42 Crunch API Protection
Defense Evasion
42 Crunch API Protection
Discovery Initial Access
42 Crunch API Protection
Credential Access Initial Access
Waf
Defense Evasion Execution Initial Access Privilege Escalation
T1211 T1059 T1190 T0890
Waf
Initial Access Execution
T1189 T1203 T0853
Azure Active Directory
Persistence Privilege Escalation
T1078
Azure Active Directory
Persistence Privilege Escalation
T1078
Microsoft Defender Advanced Threat Protection
Persistence
T1137
Argoscloud Security
Initial Access
Microsoft Threat Protection
Defense Evasion
T1211
Azure Active Directory
Initial Access Persistence
T1078 T1098
Azure Active Directory
Initial Access
T1078
Microsoft Threat Protection Security Events
Execution
T1204
Azure Active Directory
Initial Access
T1078
Azure Active Directory Behavior Analytics
Persistence
T1098
Azure Active Directory
Persistence
T1098
Azure Active Directory Behavior Analytics
Initial Access
T1078
Microsoft Threat Protection
Impact
T1486
Microsoft Threat Protection
Impact
T1486
Microsoft Threat Protection
Impact
T1486
Microsoft Threat Protection
Initial Access
T1190
Microsoft Threat Protection
Persistence
T1053
Microsoft Threat Protection
Impact
T1485
Microsoft Threat Protection
Impact
T1486
Azure Activity
Defense Evasion
T1578
Azure Activity
Defense Evasion
T1578
Azure Activity
Credential Access Defense Evasion
T1528 T1550
Azure Active Directory
Initial Access
T1078
Security Events Windows Forwarded Events Windows Security Events
Collection
T1005
Security Events Windows Forwarded Events Windows Security Events
Collection
T1005
Azure Active Directory
Defense Evasion
T1036
Azure Active Directory
Persistence Impact
T1098 T1078
Azure Active Directory
Defense Evasion
T1036
Execution Impact
T1496 T1559
Execution Defense Evasion
T1578 T1569
Persistence Impact
T1098 T1496
Persistence Impact
T1098 T1496
Azure Activity
Defense Evasion
T1562
Azure Key Vault
Credential Access
T1003
Azure Active Directory
Initial Access
T1199
Senserva Pro
Impact
T1529 T1498
Senserva Pro
Credential Access
T1212 T1556
Senserva Pro
Credential Access
T1056
Senserva Pro
Credential Access
T1555 T1606 T1040
Azure Activity
Lateral Movement Credential Access
T1570 T1212
Azure Activity Microsoft Threat Protection
Lateral Movement Execution
T1570 T1059
Security Events Windows Forwarded Events Windows Security Events
Execution Defense Evasion
T1059 T1027 T1140
Execution Defense Evasion
T1059 T1027 T1140
Zscaler
Command and Control
T1071
Bitglass
Initial Access
T1078
Bitglass
Initial Access
T1078
Bitglass
Credential Access
T1110
Bitglass
Exfiltration
T1567
Bitglass
Privilege Escalation
T1078
Bitglass
Initial Access
T1078
Bitglass
Exfiltration
T1567
Bitglass
Defense Evasion
T1070
Bitglass
Initial Access
T1078
Bitglass
Initial Access
T1078
Box Data Connector
Collection
T1530
Box Data Connector
Initial Access
T1189
Box Data Connector
Exfiltration
T1048
Box Data Connector
Initial Access
T1189
Box Data Connector
Initial Access
T1078
Box Data Connector
Exfiltration
T1537
Box Data Connector
Impact
T1485
Box Data Connector
Initial Access Persistence
T1078
Box Data Connector
Privilege Escalation
T1078
Box Data Connector
Privilege Escalation
T1078
Azure Active Directory
Credential Access
T1110
Azure Active Directory
Credential Access
T1110
Azure Active Directory
Credential Access
T1110
Salesforce Service Cloud
Credential Access
T1110
Azure Active Directory
Privilege Escalation
T1078
Windows Forwarded Events
Persistence
T1546
Security Events
Defense Evasion
T1036
Security Events
Defense Evasion
T1036
Security Events
Defense Evasion
T1036
Aws Awss3
Privilege Escalation Lateral Movement
T1078 T1563
Azure Active Directory
Persistence Privilege Escalation
T1078
Azure Active Directory
Persistence Privilege Escalation
T1078
Aws Awss3
Persistence
T1098
Aws Awss3
Persistence
T1098
Aws Awss3
Persistence
T1098
Azure Active Directory
Privilege Escalation
T1078
Windows Forwarded Events
Impact
T1496
Azure Active Directory Cisco Asa
Initial Access
T1078
Cisco Asa
Discovery Impact
T1046 T1498
Cisco Asa
Discovery Impact
T1046 T1498
Cisco Duo Security
Impact
T1489
Cisco Duo Security
Persistence
T1078
Cisco Duo Security
Persistence Privilege Escalation
T1078
Cisco Duo Security
Impact
T1531
Cisco Duo Security
Initial Access
T1078
Cisco Duo Security
Initial Access
T1078
Cisco Duo Security
Initial Access
T1078
Cisco Duo Security
Impact
T1531
Cisco Duo Security
Initial Access
T1078
Cisco Duo Security
Initial Access
T1078
Cisco Secure Endpoint
Command and Control
T1071
Cisco Secure Endpoint
Execution
T1204
Cisco Secure Endpoint
Execution
T1204
Cisco Secure Endpoint
Execution
T1204
Cisco Secure Endpoint
Initial Access
T1190 T1133
Cisco Secure Endpoint
Initial Access
T1190 T1133
Cisco Secure Endpoint
Defense Evasion
T1562
Cisco Secure Endpoint
Command and Control
T1102
Cisco Secure Endpoint
Impact
T1486
Cisco Secure Endpoint
Initial Access
T1190 T1133
Cisco Secure Endpoint
Execution Initial Access
Cisco Seg
Exfiltration
T1030
Cisco Seg
Initial Access
T1566
Cisco Seg
Exfiltration
T1030
Cisco Seg
Initial Access
T1566
Cisco Seg
Initial Access
T1566
Cisco Seg
Initial Access
T1566
Cisco Seg
Initial Access
T1566
Cisco Seg
Initial Access
T1566
Cisco Seg
Initial Access
T1566
Cisco Seg
Initial Access
T1566
Cisco Seg
Initial Access
T1566
Cisco Umbrella Data Connector
Command and Control Exfiltration
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control Initial Access
Cisco Umbrella Data Connector
Initial Access
Cisco Umbrella Data Connector
Command and Control
Cisco Umbrella Data Connector
Command and Control Defense Evasion
Cisco Wsa
Initial Access
T1566
Cisco Wsa
Initial Access
T1189
Cisco Wsa
Initial Access
T1189
Cisco Wsa
Initial Access Command and Control
T1189 T1102
Cisco Wsa
Command and Control
T1102
Cisco Wsa
Initial Access
T1189
Cisco Wsa
Exfiltration
T1048
Cisco Wsa
Initial Access
T1189
Cisco Wsa
Exfiltration
T1567
Cisco Wsa
Command and Control
T1102
Cisco Wsa
Initial Access
T1189
Cisco Ise
Initial Access Persistence Privilege Escalation Defense Evasion Execution
Cisco Ise
Credential Access
Cisco Ise
Initial Access Persistence Privilege Escalation Defense Evasion Execution
Cisco Ise
Credential Access
Cisco Ise
Initial Access Persistence Privilege Escalation Defense Evasion
Claroty
Initial Access
T1190 T1133
Claroty
Initial Access
T1190 T1133
Claroty
Initial Access
T1190 T1133
Claroty
Initial Access
T1190 T1133
Symantec Vip
Credential Access
T1110
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Persistence Command and Control
T1505 T1071
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Cloudflare Data Connector
Initial Access
T1190 T1133
Aws
Privilege Escalation
T1484
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Cognni Sentinel Data Connector
Collection
T1530
Security Events
Privilege Escalation
T1543
Microsoft Threat Protection Security Events
Persistence
T1574
Microsoft Threat Protection
Persistence Privilege Escalation
T1546
Azure Active Directory
Defense Evasion
T1078
Contrast Protect
Initial Access Exfiltration
T1566
Contrast Protect
Initial Access Exfiltration
T1566
Contrast Protect
Initial Access Exfiltration
T1566
Contrast Protect
Initial Access Exfiltration
T1566
Corelight
Command and Control
Corelight
Defense Evasion Command and Control
T1090
Corelight
Credential Access
T1187
Corelight
Exfiltration
T1030
Corelight
Initial Access
T1566
Corelight
Initial Access
T1566
Corelight
Persistence
T1505
Corelight
Persistence
T1505
Corelight
Initial Access
T1566
Azure Active Directory Identity Protection Behavior Analytics
Initial Access
T1078
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Azure Activity
Defense Evasion
T1578
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Azure Active Directory
Credential Access
Security Events
Credential Access
T1003
Security Events
Credential Access
T1003
Azure SQL
Initial Access
T1190
Check Point Fortinet Palo Alto Networks Zscaler
Exfiltration Command and Control
T1567 T1102
Check Point Fortinet Palo Alto Networks Zscaler
Exfiltration Command and Control
T1567 T1102
Crowd Strike Falcon Endpoint Protection
Crowd Strike Falcon Endpoint Protection
Vmware Carbon Black
Lateral Movement
T1210
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Cyber Ark Epm
Execution
T1204
Cyber Ark Epm
Defense Evasion
T1127
Cyber Ark Epm
Execution
T1204
Cyber Ark Epm
Execution
T1204
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cyber Ark Epm
Execution Defense Evasion Command and Control
T1204 T1036 T1095
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Cyber Ark Epm
Execution Defense Evasion
T1204 T1036
Microsoft Threat Protection
Lateral Movement
T1021
Security Events Windows Security Events
Lateral Movement
T1021
Io T
Inhibit Response Function
T0814
Microsoft Threat Protection
Execution
T1204
Azure Security Center
Impact
T1496
Command and Control
T1568 T1573 T1008
Command and Control
T1568 T1573 T1008
Command and Control
T1568 T1008
Command and Control
T1568 T1008
Azure Active Directory
Persistence Privilege Escalation
T1098 T1078
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control Lateral Movement Execution Initial Access
T1095 T1059 T1203 T1190
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control Execution Initial Access
T1095 T1059 T1203 T1190
Azure Active Directory Azure Activity Azure Security Center Office365
Initial Access Privilege Escalation
T1078 T1548
Security Events
Lateral Movement
T1021
Microsoft Threat Protection
Impact
T1490
Microsoft Threat Protection
Impact
T1490
Microsoft Threat Protection
Impact
T1490
Syslog
Command and Control
Azure Activity
Command and Control
Microsoft Defender Advanced Threat Protection Microsoft Threat Protection
Credential Access Execution
T1569 T1003
Credential Access Execution
T1569 T1003
Microsoft Threat Protection Security Events
Exfiltration Defense Evasion
T1048 T1562
Microsoft Threat Protection Security Events
Persistence
T1098
Microsoft Threat Protection Security Events
Impact
T1486
Microsoft Threat Protection Security Events
Discovery
T1482
Microsoft Threat Protection
Impact
T1486
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Digital Guardian Dlp
Exfiltration
T1048
Microsoft Threat Protection
Defense Evasion
T1562
Zscaler
Command and Control
T1071
Squid Proxy Zscaler
Command and Control
T1071
Azure Active Directory
Credential Access
T1110
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Windows Forwarded Events Zscaler
Impact
T1496
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Zscaler
Exfiltration
T1048
Azure SQL
Initial Access
T1190
Security Events
Persistence
T1098
Security Events
Credential Access
T1003
Dynamics365
Collection
T1530
Dynamics365
Defense Evasion
T1600
Dynatrace Attacks
Execution Impact Initial Access Privilege Escalation
T1059 T1565 T1190 T1068
Dynatrace Runtime Vulnerabilities
Defense Evasion Execution Impact Initial Access Lateral Movement Persistence Privilege Escalation
Dynatrace Runtime Vulnerabilities
Defense Evasion Execution Impact Initial Access Lateral Movement Persistence Privilege Escalation
Dynatrace Runtime Vulnerabilities
Defense Evasion Execution Impact Initial Access Lateral Movement Persistence Privilege Escalation
Windows Security Events
Initial Access
T1078
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Privilege Escalation
T1068 T1078
Azure Active Directory
Persistence Privilege Escalation
T1078
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Windows Firewall
Command and Control Credential Access
T1071 T1003
Sophos Xgfirewall
Impact
T1499
Symantec Endpoint Protection
Symantec Proxy Sg
Defense Evasion
Symantec Vip
Credential Access
T1110
Io T
Impair Process Control
T0806
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Impact
T1499
Squid Proxy Zscaler
Persistence Credential Access
T1110 T1556
Infoblox Nios
Command and Control
T1568 T1008
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Zscaler
Command and Control
T1568 T1008
Security Events
Collection Discovery
T1039 T1135
Security Events Windows Security Events
Credential Access
T1110
Office365
Defense Evasion
T1562
Security Events Windows Security Events
Initial Access
T1190
Azure Monitor( Iis)
Initial Access
T1190
Azure Monitor( Iis) Microsoft Threat Protection
Execution
T1059 T1059
Azure SQL
Initial Access
T1190
Azure Active Directory
Credential Access
T1528
Azure Active Directory
Credential Access
T1110
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Credential Access Persistence
T1098 T1556
Office365
Persistence
T1136
Aws Azure Active Directory
Initial Access Credential Access
T1078 T1110
Aws Azure Active Directory
Initial Access Credential Access
T1078 T1110
Azure Active Directory Security Events Syslog Windows Forwarded Events Windows Security Events
Initial Access Credential Access
T1078 T1110
Azure Active Directory Security Events Syslog Windows Forwarded Events Windows Security Events
Initial Access Credential Access
T1078 T1110
Azure Active Directory
Credential Access
T1110
Okta Sso
Credential Access
T1110
Security Events Windows Forwarded Events Windows Security Events
Credential Access
T1110
Syslog
Credential Access
T1110
Azure Active Directory Last Pass
Initial Access
T1078 T1190
Security Events
Defense Evasion
T1564
Azure SQL
Initial Access
T1190
Azure SQL
Initial Access
T1190
Azure Active Directory
Defense Evasion
T1550
Flare
Credential Access
T1555
Flare
Credential Access
T1110
Flare
Resource Development
T1583
Fortinet
Command and Control
T1071 T1571
Forti Web
Initial Access
T1190 T1133
Waf
Defense Evasion Execution Initial Access Privilege Escalation
T1211 T1059 T1190 T0890
Waf
Initial Access Execution
T1189 T1203 T0853
Aws Awss3
Privilege Escalation
Azure Active Directory
Defense Evasion
T1550
Security Events Windows Forwarded Events Windows Security Events
Lateral Movement
T1210
Security Events Windows Security Events
Lateral Movement
T1210
Gcpiamdata Connector
Defense Evasion
T1562
Gcpiamdata Connector
Defense Evasion
T1550
Gcpiamdata Connector
Privilege Escalation
T1078
Gcpiamdata Connector
Lateral Movement
T1550
Gcpiamdata Connector
Persistence
T1136
Gcpiamdata Connector
Lateral Movement
T1550
Gcpiamdata Connector
Discovery
T1069
Gcpiamdata Connector
Discovery
T1069
Gcpiamdata Connector
Discovery
T1087
Gcpiamdata Connector
Discovery
T1069
Azure Active Directory
Credential Access
T1110
Syslog
Credential Access
T1110
Syslog
Credential Access
T1110
Syslog
Persistence Defense Evasion Credential Access
T1556
Azure Active Directory
Credential Access
T1110
Syslog Threat Intelligence Threat Intelligence Taxii
Initial Access
T1078
Gcpdnsdata Connector
Privilege Escalation
T1068
Gcpdnsdata Connector
Privilege Escalation
T1068
Gcpdnsdata Connector
Privilege Escalation
T1068
Gcpdnsdata Connector
Initial Access Credential Access
T1566 T1187
Gcpdnsdata Connector
Command and Control
T1095
Gcpdnsdata Connector
Initial Access
T1195
Gcpdnsdata Connector
Command and Control
T1095
Gcpdnsdata Connector
Command and Control
T1095
Gcpdnsdata Connector
Exfiltration
T1567
Gcpdnsdata Connector
Command and Control
T1095
Gcpdnsdata Connector
Command and Control
T1095
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Azure Active Directory
Initial Access Persistence Discovery
T1078 T1136 T1087
Azure Active Directory
Persistence
T1078
Google Workspace Reports API
Persistence
T1098
Google Workspace Reports API
Initial Access
T1190 T1133
Google Workspace Reports API
Collection
T1114
Google Workspace Reports API
Defense Evasion Lateral Movement
T1550
Google Workspace Reports API
Persistence Collection
T1185 T1176
Google Workspace Reports API
Credential Access
T1110
Google Workspace Reports API
Initial Access
T1566
Google Workspace Reports API
Credential Access
T1111
Google Workspace Reports API
Privilege Escalation
Google Workspace Reports API
Persistence
T1098
Azure Monitor( Iis)
Initial Access
T1190
Azure Monitor( Iis)
Credential Access
T1110
Azure Monitor( Iis)
Credential Access
T1110
Qualys Vulnerability Management
Initial Access
T1190
Qualys Vulnerability Management
Initial Access
T1190
Cyberpion Security Logs
Initial Access
T1190 T1195
Last Pass
Credential Access Discovery
T1555 T1087
Microsoft Threat Protection
Persistence Privilege Escalation Defense Evasion
T1574
Microsoft Threat Protection Security Events
Lateral Movement
T1570
Microsoft Threat Protection Security Events
Initial Access
T1190
Io T
Impair Process Control
T0855
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Imperva Wafcloud API
Initial Access
T1190 T1133
Infoblox Cloud Data Connector
Impact
T1498 T1565
Infoblox Cloud Data Connector
Impact
T1498 T1565
Infoblox Cloud Data Connector
Impact
T1498 T1565
Microsoft Threat Protection
Command and Control Defense Evasion
T1105 T1564 T1027 T1140
Azure Active Directory Identity Protection Azure Security Center Io T Microsoft Cloud App Security Microsoft Defender Advanced Threat Protection Office Atp
Execution
T1204
Azure Active Directory Identity Protection Azure Security Center Io T Microsoft Cloud App Security Microsoft Defender Advanced Threat Protection Office Atp
Execution
T1204
Azure Active Directory
Execution
T1204
Azure Active Directory Azure Information Protection
Exfiltration
T1567
Io T
Lateral Movement
T0886
Check Point Fortinet Microsoft Threat Protection Palo Alto Networks Zscaler
Exfiltration Command and Control
T1041 T1071
Azure Active Directory Palo Alto Networks
Initial Access Credential Access
T1078 T1110
Jamf Protect
Initial Access
Jira Audit API
Privilege Escalation
T1078
Jira Audit API
Initial Access
T1078
Jira Audit API
Persistence Privilege Escalation
T1078
Jira Audit API
Persistence
T1078
Jira Audit API
Impact
T1531
Jira Audit API
Impact
T1531
Jira Audit API
Impact
T1531
Jira Audit API
Impact
T1531
Jira Audit API
Persistence
T1078
Jira Audit API
Collection
T1213
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Palo Alto Networks Zscaler
Command and Control
T1071
Vmware Carbon Black
Execution
T1204
Security Events
Lateral Movement
T1021
Microsoft Cloud App Security
Command and Control Exfiltration
T1071 T1567
Aws Azure Active Directory Azure Activity Azure Firewall Azure Monitor( Iis) Azure Monitor( Vminsights) Azure Monitor( Wire Data) Cisco Asa DNS Microsoft Threat Protection Office365 Palo Alto Networks Security Events
Command and Control
Aws Awss3
Defense Evasion Privilege Escalation Persistence Initial Access
T1078
Lookout API
Discovery
T1057
Office365
Collection Exfiltration
T1114 T1020
Azure Active Directory
Persistence
T1098
Aws Azure Active Directory Azure Monitor( Iis) Office365 Waf
Initial Access Command and Control Execution
T1189 T1071 T1203
Office365
Persistence Defense Evasion
T1098 T1078
Azure Monitor( Iis) Microsoft Defender Advanced Threat Protection
Persistence
T1505
Proofpoint Tap
Initial Access
T1566
Symantec Endpoint Protection
Execution
Security Events Windows Forwarded Events Windows Security Events
Defense Evasion
Proofpoint Tap
Initial Access
T1566
Azure Activity
Impact
T1485
Microsoft Cloud App Security Microsoft Threat Protection
Exfiltration
T1052
Dynamics365
Collection
T1530
Azure Key Vault
Credential Access
T1003
Microsoft Threat Protection
Defense Evasion
T1036
MC Afeee Po
Defense Evasion
T1562
MC Afeee Po
Defense Evasion
T1562 T1070
MC Afeee Po
Defense Evasion
T1562
MC Afeee Po
Defense Evasion
T1562 T1070
MC Afeee Po
Defense Evasion
T1562 T1070
MC Afeee Po
Defense Evasion Command and Control
T1562 T1071
MC Afeee Po
Defense Evasion
T1562 T1070
MC Afeee Po
Initial Access Persistence Defense Evasion Privilege Escalation
T1562 T1070 T1189 T1195 T1543 T1055
MC Afeee Po
Defense Evasion
T1562 T1070
MC Afeee Po
Initial Access
T1566
MC Afeee Po
Defense Evasion
T1562 T1070
MC Afeee Po
Initial Access Privilege Escalation Defense Evasion
T1562 T1070 T1068 T1189 T1195
MC Afeee Po
Defense Evasion
T1562 T1070
MC Afeee Po
Defense Evasion
T1562 T1070
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Windows Firewall
Command and Control
T1071
Azure Active Directory
Initial Access
T1078
Microsoft Threat Protection
Initial Access
T1190
Security Events Windows Forwarded Events Windows Security Events
Execution
T1059
Security Events Windows Forwarded Events Windows Security Events
Persistence
T1547
Security Events
Persistence
T1546
Azure Active Directory
Credential Access
Aws Azure Active Directory
Credential Access Persistence
T1098 T1556
Azure Active Directory
Impact
T1531
Azure Active Directory Office365 Security Events Syslog Windows Forwarded Events Windows Security Events
Initial Access Credential Access
T1078 T1110
Security Events Windows Forwarded Events Windows Security Events
Lateral Movement
T1021
Azure Firewall
Exfiltration Command and Control
Office365
Impact
T1485 T1489
Office365
Collection Exfiltration
T1114 T1020
Office365
Collection Exfiltration
T1114 T1020
Security Events Trend Micro Windows Forwarded Events Windows Security Events
Execution
T1204
Azure Active Directory
Defense Evasion
T1550
Azure Activity
Execution
T1059
Dynamics365
Initial Access
T1078
Dynamics365
Initial Access
T1078
Security Events Windows Security Events
Execution Lateral Movement
T1072 T1570
Security Events
Execution Lateral Movement
T1072 T1570
Office365
Command and Control
T1105
Azure Active Directory
Persistence
T1098
Qualys Vulnerability Management
Initial Access
T1190
Qualys Vulnerability Management
Initial Access
T1190
Dynamics365
Initial Access
T1078
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Aws Azure Monitor( Iis) Office365
Initial Access Command and Control Execution
T1189 T1071 T1203
Nginxhttpserver
Initial Access
T1190 T1133
Nginxhttpserver
Impact
T1499
Nginxhttpserver
Initial Access
T1190 T1133
Nginxhttpserver
Initial Access
T1190 T1133
Nginxhttpserver
Impact Initial Access
T1498 T1190 T1133
Nginxhttpserver
Initial Access
T1190 T1133
Nginxhttpserver
Initial Access
T1190 T1133
Nginxhttpserver
Initial Access
T1190 T1133
Nginxhttpserver
Initial Access
T1189
Nginxhttpserver
Initial Access
T1190
Io T
Inhibit Response Function
T0881
Security Events Windows Security Events
Credential Access
T1003
Senserva Pro
Initial Access
T1078
Azure Active Directory
Persistence
T1098
Azure Activity
Defense Evasion
T1578
Security Events Windows Security Events
Execution Defense Evasion
T1059 T1027 T1140
Azure Activity
Defense Evasion
T1578
Azure Active Directory
Defense Evasion
T1550
Aws Awss3
Defense Evasion Privilege Escalation Persistence Initial Access
T1078
Office365
Persistence Defense Evasion
T1098 T1078
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Credential Access
Office365
Collection Exfiltration
T1114 T1020
Azure Active Directory
Defense Evasion
T1550
Azure Active Directory
Persistence
T1078
Azure Active Directory
Privilege Escalation
T1078
Security Events Windows Security Events
Execution Defense Evasion
T1059 T1027 T1140
Security Events Windows Security Events
Defense Evasion
T1070
Azure Key Vault
Impact
T1485
Syslog
Command and Control
T1102
Azure Active Directory
Persistence Privilege Escalation
T1098 T1078
Oracle Cloud Infrastructure Logs Connector
Discovery
T1580
Oracle Cloud Infrastructure Logs Connector
Defense Evasion
T1070
Oracle Cloud Infrastructure Logs Connector
Initial Access
T1190
Oracle Cloud Infrastructure Logs Connector
Discovery
T1069
Oracle Cloud Infrastructure Logs Connector
Discovery
T1069
Oracle Cloud Infrastructure Logs Connector
Impact
T1496
Oracle Cloud Infrastructure Logs Connector
Impact
T1529
Oracle Cloud Infrastructure Logs Connector
Reconnaissance
T1595
Oracle Cloud Infrastructure Logs Connector
Reconnaissance
T1595
Oracle Cloud Infrastructure Logs Connector
Initial Access
T1190
Microsoft Threat Protection
Initial Access
T1566
Office365
Persistence Defense Evasion
T1098 T1562
Azure SQL
Initial Access
T1190
Oracle Web Logic Server
Initial Access
T1190 T1133
Oracle Web Logic Server
Initial Access
T1190 T1133
Oracle Web Logic Server
Initial Access
T1190 T1133
Oracle Web Logic Server
Impact Initial Access
T1498 T1190 T1133
Oracle Web Logic Server
Initial Access
T1190 T1133
Oracle Web Logic Server
Initial Access
T1190
Oracle Web Logic Server
Initial Access
T1190 T1133
Oracle Web Logic Server
Initial Access
T1190 T1133
Oracle Web Logic Server
Initial Access Exfiltration
T1190 T1133 T1048
Oracle Web Logic Server
Initial Access
T1189
Microsoft Threat Protection
Lateral Movement Privilege Escalation
T1210 T1611
Oracle Database Audit
Initial Access Collection Exfiltration
T1190 T1133 T1078 T1119 T1029
Oracle Database Audit
Initial Access
T1078
Oracle Database Audit
Impact
T1485
Oracle Database Audit
Initial Access Persistence
T1078
Oracle Database Audit
Collection
Oracle Database Audit
Impact
T1529
Oracle Database Audit
Initial Access
T1190
Oracle Database Audit
Collection
T1119
Oracle Database Audit
Initial Access Persistence
T1078
Oracle Database Audit
Initial Access
T1078
Azure SQL
Initial Access
T1190
Palo Alto Networks
Discovery
T1046
Palo Alto Networks
Command and Control
T1071 T1571
Palo Alto Networks
Command and Control
T1071 T1571
Palo Alto Networks Cortex
Defense Evasion
T1562
Palo Alto Prisma Cloud
Initial Access
T1078
Palo Alto Prisma Cloud
Initial Access
T1078
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Initial Access
T1078
Palo Alto Prisma Cloud
Initial Access
T1078
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Credential Access
T1110
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Prisma Cloud
Initial Access
T1133
Palo Alto Networks
Discovery Exfiltration Command and Control
T1046 T1030 T1071
Palo Alto Networks Cortex
Defense Evasion
T1562
Palo Alto Cdl
Initial Access
T1190 T1133
Palo Alto Cdl
Initial Access
T1190 T1133
Palo Alto Cdl
Initial Access
T1190 T1133
Palo Alto Cdl
Initial Access
T1190 T1133
Palo Alto Cdl
Initial Access
T1190 T1133
Palo Alto Cdl
Initial Access
T1190 T1133
Palo Alto Cdl
Initial Access
T1190 T1133
Palo Alto Cdl
Reconnaissance
T1595
Palo Alto Cdl
Initial Access
T1190 T1133
Palo Alto Cdl
Initial Access
T1190 T1133
Azure Active Directory
Credential Access
T1110
Azure Active Directory
Credential Access
T1110
Microsoft Threat Protection
Credential Access
T1110
Microsoft Threat Protection
Execution
T1203
Azure Active Directory
Persistence
T1078
Ping Federate
Credential Access
T1110
Ping Federate
Initial Access Persistence Privilege Escalation
T1078 T1098 T1134
Ping Federate
Initial Access
T1078
Ping Federate
Initial Access
T1078
Ping Federate
Initial Access Persistence
T1078 T1136
Ping Federate
Initial Access
T1190
Ping Federate
Initial Access
T1078
Ping Federate
Initial Access
T1190
Ping Federate
Initial Access
T1078
Ping Federate
Initial Access
T1078
Ping Federate
Initial Access
T1078
Azure Firewall
Discovery
T1046
Sophos Xgfirewall
Discovery
T1046
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Discovery
T1046
Azure Firewall
Discovery
T1046
Azure Active Directory Zscaler
Initial Access Defense Evasion Credential Access
T1078 T1557 T1111
Barracuda Cef Check Point Cisco Asa F5 Fortinet Palo Alto Networks Zscaler
Command and Control
T1568
Office365
Credential Access
T1110
Aivectra Stream Awss3 Azure Monitor( Vminsights) Azure Nsg Check Point Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Initial Access Command and Control
T1566 T1102
Security Events
Privilege Escalation
T1134
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Meraki Corelight Fortinet Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Command and Control
T1071 T1571
Security Events Windows Forwarded Events Windows Security Events
Persistence
T1554
Microsoft Threat Protection
Persistence
T1554
Squid Proxy Zscaler
Command and Control
T1568
DNS
Command and Control
T1568 T1008
Azure Firewall Cisco Umbrella Data Connector Corelight DNS Gcpdnsdata Connector Infoblox Nios Nxlog DNS Logs Zscaler
Command and Control
T1568 T1008
Command and Control
T1568 T1008
Command and Control
T1568 T1008
Infoblox Nios
Initial Access
T1200
Security Events Windows Security Events
Privilege Escalation
T1548
Privilege Escalation
T1548
Security Events Windows Forwarded Events Windows Security Events
Credential Access
T1558
Salesforce Service Cloud
Credential Access
T1110
Okta Sso
Credential Access
T1110
Security Events Windows Security Events
Defense Evasion Impact
T1485 T1036
Defense Evasion Impact
T1485 T1036
Security Events
Command and Control
T1572
Security Events Windows Forwarded Events Windows Security Events
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Lateral Movement Persistence Privilege Escalation
T1548 T1134 T1134 T1134 T1087 T1087 T1557 T1071 T1560 T1547 T1547 T1547 T1217 T1115 T1059 T1059 T1059 T1136 T1136 T1543 T1555 T1484 T1482 T1114 T1573 T1546 T1041 T1567 T1567 T1068 T1210 T1083 T1615 T1574 T1574 T1574 T1574 T1574 T1070 T1105 T1056 T1056 T1106 T1046 T1135 T1040 T1027 T1003 T1057 T1055 T1021 T1021 T1053 T1113 T1518 T1558 T1558 T1082 T1016 T1049 T1569 T1127 T1552 T1552 T1550 T1125 T1102 T1047
Microsoft Threat Protection Security Events
Execution
T1203
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Aws
Privilege Escalation
T1484
Azure Active Directory Behavior Analytics
Privilege Escalation
T1078
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory Behavior Analytics
Defense Evasion
T1078
Microsoft Threat Protection
Discovery
T1018
Security Events Windows Forwarded Events Windows Security Events
Execution Defense Evasion
T1059 T1027 T1140
Security Events Windows Security Events
Execution
T1059
Proofpoint Pod
Initial Access
T1078
Proofpoint Pod Threat Intelligence Threat Intelligence Taxii
Exfiltration Initial Access
T1078 T1567
Proofpoint Pod Threat Intelligence Threat Intelligence Taxii
Exfiltration Initial Access
T1078 T1567
Proofpoint Pod
Initial Access
T1566
Proofpoint Pod
Exfiltration
T1567
Proofpoint Pod
Exfiltration
T1567
Proofpoint Pod
Exfiltration
T1567
Proofpoint Pod
Initial Access
T1078
Proofpoint Pod
Initial Access
T1566
Proofpoint Pod
Commandand Control
T1573
Pulse Connect Secure
Initial Access
T1190
Pulse Connect Secure
Credential Access
T1110
Pulse Connect Secure
Credential Access
T1110
Office365
Persistence Collection
T1098 T1114
Azure Active Directory
Persistence Privilege Escalation
T1136 T1068
Security Events Windows Forwarded Events Windows Security Events
Lateral Movement
T1021
Azure Activity
Credential Access Persistence
T1003 T1098
Security Events Windows Forwarded Events Windows Security Events
Lateral Movement
T1021
Red Canary Data Connector
Collection Command and Control Credential Access Defense Evasion Discovery Execution Exfiltration Impact Initial Access Lateral Movement Persistence Privilege Escalation
Security Events
Persistence
T1546
Security Events
Persistence
T1546
Microsoft Threat Protection
Lateral Movement
T1021
Microsoft Threat Protection
Defense Evasion
T1036
Zscaler
Command and Control
T1102 T1071
Azure SQL
Exfiltration
T1537 T1567
Check Point Fortinet Palo Alto Networks Zscaler
Exfiltration Command and Control
T1041 T1071
Sail Point Identity Now
Initial Access Collection
T1133 T1005
Sail Point Identity Now
Initial Access
T1133
Sail Point Identity Now
Initial Access
T1133
Sail Point Identity Now
Initial Access
T1133
Sail Point Identity Now
Initial Access
T1133
Sail Point Identity Now
Initial Access
T1133
Security Events Windows Security Events
Defense Evasion
T1562
Security Events Windows Security Events
Impact
T1485
Security Events Windows Forwarded Events Windows Security Events
Defense Evasion
T1070
Microsoft Threat Protection Security Events Windows Forwarded Events Windows Security Events
Defense Evasion
T1562
Security Bridge
Initial Access
Security Events Windows Security Events
Credential Access
T1110
Semperis Dsp
Credential Access
Semperis Dsp
Defense Evasion
T1207
Semperis Dsp
Privilege Escalation
Semperis Dsp
Privilege Escalation Defense Evasion
T1134
Semperis Dsp
Privilege Escalation
Senserva Pro
Impact
T1529 T1485
Azure Key Vault
Impact
T1485
Microsoft Azure Purview
Discovery
T1087
Microsoft Azure Purview
Discovery
T1087
Sentinel One
Initial Access Privilege Escalation
T1078
Sentinel One
Defense Evasion
T1070
Sentinel One
Initial Access
Sentinel One
Defense Evasion
T1070
Sentinel One
Defense Evasion
T1070
Sentinel One
Initial Access
Sentinel One
Privilege Escalation
T1078
Sentinel One
Defense Evasion
T1070
Sentinel One
Defense Evasion
T1070
Sentinel One
Initial Access
Sentinel One
Credential Access
T1555
Esi Exchange Admin Audit Log Events
Exfiltration Persistence Collection
T1020 T1098 T1114
Security Events Windows Security Events
Execution
T1569
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Initial Access
T1078
Security Events
Privilege Escalation
T1134
Senserva Pro
Initial Access
T1078
Azure Firewall
Discovery Lateral Movement Command and Control
T1046 T1071 T1210
Office365
Exfiltration
T1030
Office365
Exfiltration
T1030
Azure Active Directory
Initial Access Persistence
T1078 T1098
Initial Access Persistence
T1078 T1098
Security Events Windows Forwarded Events Windows Security Events
Initial Access
T1190
Azure Monitor( Iis)
Initial Access
T1190
Slack Audit API
Initial Access
T1133
Slack Audit API
Exfiltration
T1567
Slack Audit API
Credential Access
T1110
Slack Audit API
Exfiltration
T1048
Slack Audit API
Initial Access
T1189
Slack Audit API
Persistence
Slack Audit API
Initial Access
T1078
Slack Audit API
Initial Access Persistence Privilege Escalation
T1078
Slack Audit API
Persistence Privilege Escalation
T1098 T1078
Microsoft Threat Protection
Lateral Movement
T1021
Snowflake
Discovery
T1518 T1082
Snowflake
Initial Access
T1078
Snowflake
Initial Access
T1078
Snowflake
Privilege Escalation
T1078
Microsoft Defender Advanced Threat Protection Microsoft Threat Protection
Initial Access
T1195
Security Events Windows Forwarded Events Windows Security Events
Defense Evasion Privilege Escalation
T1055
Syslog
Command and Control
T1090 T1008
Syslog
Command and Control
T1102
Syslog
Credential Access
T1110
Senserva Pro
Initial Access
T1566
Azure Firewall Azure Monitor( Vminsights) Cisco Asa Microsoft Threat Protection Palo Alto Networks
Initial Access
T1566
Security Events Windows Security Events
Defense Evasion
T1562
Azure Activity
Impact
T1496
Azure Active Directory
Credential Access Initial Access
T1110 T1078
Microsoft Threat Protection
Execution Persistence Initial Access
T1195 T1059 T1546
Execution Persistence Initial Access
T1195 T1059 T1546
Microsoft Threat Protection
Execution Persistence Initial Access
T1195 T1059 T1546
Microsoft Threat Protection
Execution Persistence
Microsoft Threat Protection
Persistence
T1554
Azure Monitor( Iis)
Persistence Command and Control
T1505 T1071
Azure Active Directory
Credential Access
T1528
Azure Active Directory
Credential Access
T1528
Azure Active Directory
Credential Access Defense Evasion
T1528 T1550
Azure Active Directory
Credential Access Defense Evasion
T1528 T1550
Azure Activity Behavior Analytics
Persistence Privilege Escalation
T1098 T1548
Credential Access Persistence
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory Behavior Analytics
Privilege Escalation
T1078
Microsoft Threat Protection
Execution Defense Evasion
T1559 T1055
Azure Activity
Impact
T1496
Microsoft Threat Protection
Initial Access
T1566
Microsoft Threat Protection
Execution
T1204
Azure Activity
Impact
T1496
Azure Active Directory
Credential Access Privilege Escalation Initial Access
T1078 T1528
Behavior Analytics
Initial Access
T1078
Azure SQL
Initial Access
T1190
Microsoft Threat Protection
Execution Persistence Defense Evasion
T1543 T1059 T1027
Tenable Ad
Credential Access
T1110
Tenable Ad
Defense Evasion
T1207
Tenable Ad
Credential Access
T1003
Tenable Ad
Credential Access
T1558
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1003
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Tenable Ad
Credential Access
T1110
Senserva Pro
Exfiltration
T1020
Office365
Collection Exfiltration
T1114 T1020
Azure Activity
Impact
T1485
Azure Active Directory
Impact
T1531
Azure Active Directory
Persistence Privilege Escalation
T1098 T1078
Azure Monitor( Vminsights) Cisco Asa Palo Alto Networks
Exfiltration
T1030
Azure Active Directory
Persistence
T1078
Eset Smc
Execution Credential Access Privilege Escalation
Esetprotect
Execution
T1204
Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
DNS Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Palo Alto Networks Threat Intelligence Threat Intelligence Taxii
Impact
Azure Security Center Microsoft Cloud App Security Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Syslog Threat Intelligence Threat Intelligence Taxii
Impact
Azure Activity Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Palo Alto Networks Threat Intelligence Threat Intelligence Taxii
Impact
Azure Security Center Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Security Events Threat Intelligence Threat Intelligence Taxii Windows Forwarded Events Windows Security Events
Impact
Azure Active Directory Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Palo Alto Networks Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Security Events Threat Intelligence Threat Intelligence Taxii Windows Forwarded Events Windows Security Events
Impact
Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Aws Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Azure Key Vault Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Azure SQL Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Azure Activity Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Azure Firewall Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Cef Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
DNS Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Cisco Duo Security Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Last Pass Threat Intelligence
Impact
T1485
Aivectra Stream Awss3 Azure Firewall Azure Monitor( Vminsights) Azure Nsg Check Point Cisco Asa Cisco Meraki Corelight Fortinet Microsoft Defender Threat Intelligence Microsoft Sysmon for Linux Microsoft Threat Protection Palo Alto Networks Security Events Windows Forwarded Events Zscaler
Impact
Microsoft Defender Threat Intelligence Office365 Threat Intelligence Threat Intelligence Taxii
Impact
Azure Active Directory Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Azure Monitor( Vminsights) Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Azure Monitor( Iis) Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Azure Active Directory Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Office365 Threat Intelligence
Impact
Microsoft Defender Threat Intelligence Palo Alto Networks Threat Intelligence Threat Intelligence Taxii
Impact
Azure Security Center Microsoft Cloud App Security Microsoft Defender Threat Intelligence Threat Intelligence Threat Intelligence Taxii
Impact
Microsoft Defender Threat Intelligence Syslog Threat Intelligence Threat Intelligence Taxii
Impact
Barracuda Cef Check Point Cisco Asa F5 Fortinet Palo Alto Networks
Exfiltration
T1030
Azure Monitor( Vminsights) Cisco Asa Palo Alto Networks
Exfiltration
T1030
Apache Tomcat
Initial Access
T1190 T1133
Apache Tomcat
Initial Access
T1190 T1133
Apache Tomcat
Initial Access
T1190 T1133
Apache Tomcat
Initial Access Impact
T1190 T1133 T1499
Apache Tomcat
Impact Initial Access
T1498 T1190 T1133
Apache Tomcat
Initial Access
T1190 T1133
Apache Tomcat
Initial Access
T1190 T1133
Apache Tomcat
Initial Access
T1189
Apache Tomcat
Impact Initial Access
T1498 T1190 T1133
Apache Tomcat
Initial Access
T1190
Trend Micro Cas
Exfiltration
T1048
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Impact
T1486
Trend Micro Cas
Impact
T1486
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Defense Evasion
T1562
Trend Micro Cas
Initial Access
T1566
Trend Micro Cas
Initial Access
T1566
Microsoft Threat Protection
Defense Evasion
T1127
Ubiquiti Unifi
Exfiltration Command and Control
T1071 T1571 T1572
Ubiquiti Unifi
Command and Control Exfiltration
T1572 T1041
Ubiquiti Unifi
Exfiltration Command and Control
T1041 T1572
Ubiquiti Unifi
Command and Control
T1071 T1095 T1571
Ubiquiti Unifi
Initial Access
T1133
Ubiquiti Unifi
Initial Access
T1133
Ubiquiti Unifi
Initial Access
T1133
Ubiquiti Unifi
Command and Control
T1090 T1572
Ubiquiti Unifi
Exfiltration
Ubiquiti Unifi
Initial Access
Microsoft Threat Protection Security Events
Persistence
T1136
Azure Active Directory
Persistence Privilege Escalation
T1078
Symantec Proxy Sg
Defense Evasion
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Azure Active Directory
Persistence
T1136
Azure Active Directory
Persistence
T1136
Security Events Windows Forwarded Events Windows Security Events
Persistence Privilege Escalation
T1098 T1078
Azure Active Directory
Initial Access
T1078
Azure Active Directory
Privilege Escalation
T1078
Azure Active Directory
Persistence Privilege Escalation
T1098 T1078
Aws Azure Active Directory Azure Monitor( Iis) Office365 Squid Proxy Waf Zscaler
Initial Access
T1190
Azure Active Directory
Persistence
T1078
Initial Access Privilege Escalation
T1078
Okta Sso
Initial Access
T1078
Salesforce Service Cloud
Initial Access
T1078
Azure Active Directory
Persistence
T1098
Senserva Pro
Initial Access
T1078
Collection Exfiltration
T1530 T1213 T1020
V Armour Ac
Discovery Lateral Movement
T1135 T1570
V Center
Privilege Escalation
T1078
Aivectra Detect
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Aivectra Detect
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Aivectra Detect
Lateral Movement Command and Control
Aivectra Detect
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Aivectra Detect
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Aivectra Detect
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Aivectra Detect
Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Esi Exchange Admin Audit Log Events
Exfiltration Persistence Collection
T1020 T1098 T1114
Vmware Esxi
Initial Access
T1190
Vmware Esxi
Initial Access
T1078
Vmware Esxi
Initial Access
T1078
Vmware Esxi
Privilege Escalation
T1078
Vmware Esxi
Initial Access Privilege Escalation
T1078
Vmware Esxi
Initial Access Privilege Escalation
T1078
V Center
Initial Access Privilege Escalation
T1078
Initial Access Execution
T1190 T1203
Initial Access Execution
T1190 T1203
Security Events
Credential Access
T1003
Eset Smc
Exfiltration Command and Control Initial Access
Esetprotect
Exfiltration Command and Control Initial Access
T1041 T1071 T1189 T1566
Security Events
Execution
T1059
Security Events
Execution
T1059
Check Point Fortinet Microsoft Threat Protection Palo Alto Networks Zscaler
Exfiltration Command and Control
T1041 T1071
Azure Active Directory Identity Protection Azure Activity Behavior Analytics
Initial Access Impact
T1078 T1489
Zero Networks Segment Audit Function Zero Networks Segment Audit Native Poller
Defense Evasion
T1562
Zero Networks Segment Audit Function Zero Networks Segment Audit Native Poller
Credential Access
T1528
Zero Networks Segment Audit Function Zero Networks Segment Audit Native Poller
Lateral Movement
T1021
Azure Firewall Azure Monitor( Vminsights) Cef Check Point Cisco Asa DNS F5 Fortinet Microsoft Threat Protection Office365 Palo Alto Networks Security Events Windows Firewall Windows Forwarded Events Windows Security Events
Persistence
T1546
Microsoft Threat Protection Security Events Windows Security Events
Persistence
T1546
Credential Access Discovery
T1040
Zscaler Private Access
Persistence
T1078
Zscaler Private Access
Initial Access
T1190 T1133
Zscaler Private Access
Initial Access
T1078 T1133
Zscaler Private Access
Initial Access
T1078 T1133
Zscaler Private Access
Initial Access
T1190 T1133
Zscaler Private Access
Initial Access
T1078 T1133
Zscaler Private Access
Persistence
T1078
Zscaler Private Access
Initial Access
T1190 T1133
Zscaler Private Access
Initial Access
T1078 T1133
Zscaler Private Access
Initial Access
T1190 T1133