Skip to content

Latest commit

 

History

History
13 lines (11 loc) · 1.43 KB

r_m_ibm_ibm_sterling_b2b_integrator_Executive_Account_Activity.md

File metadata and controls

13 lines (11 loc) · 1.43 KB

Vendor: IBM

Rules Models MITRE TTPs Event Types Parsers
2 1 2 2 2
Event Type Rules Models
failed-logon T1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
remote-logon T1078 - Valid Accounts
AL-HT-EXEC-new: New user logon to executive asset

T1068 - Exploitation for Privilege Escalation
ALERT-EXEC: Security violation by Executive
AL-HT-EXEC: Executive Assets