Skip to content

Latest commit

 

History

History
27 lines (25 loc) · 8.23 KB

ds_ibm_ibm_sametime.md

File metadata and controls

27 lines (25 loc) · 8.23 KB

Vendor: IBM

Product: IBM Sametime

Rules Models MITRE TTPs Event Types Parsers
33 14 3 2 2
Use-Case Event Types/Parsers MITRE TTP Content
Abnormal Application Access app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Abnormal Authentication & Access app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
T1133 - External Remote Services
  • 2 Rules
Abnormal User Activity app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
T1133 - External Remote Services
  • 18 Rules
  • 11 Models
Access to Application Data app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
  • 5 Rules
  • 4 Models
Compromised Service Account app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
  • 1 Rules
Disabled Account Abuse app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
  • 1 Rules
Disabled Account Activity app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
  • 1 Rules
Evasion app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1090.003 - Proxy: Multi-hop Proxy
  • 2 Rules
Malware app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
T1090.003 - Proxy: Multi-hop Proxy
  • 2 Rules
Ransomware app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
  • 2 Rules
Service Account Abuse app-login
ibm-app-login

failed-app-login
ibm-failed-app-login
T1078 - Valid Accounts
  • 1 Rules

ATT&CK Matrix for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
External Remote Services

Valid Accounts

External Remote Services

Valid Accounts

Valid Accounts

Valid Accounts

Proxy: Multi-hop Proxy

Proxy