Skip to content

Latest commit

 

History

History
153 lines (151 loc) · 68.1 KB

uc_data_leak_via_removable_device.md

File metadata and controls

153 lines (151 loc) · 68.1 KB

Use Case: Data Leak via Removable Device

Vendor: AssetView

Product Event Types MITRE TTP Content
AssetView
  • file-download
  • file-write
  • print-activity
  • security-alert
  • usb-insert
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Barracuda

Product Event Types MITRE TTP Content
Barracuda Firewall
  • failed-logon
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: CatoNetworks

Product Event Types MITRE TTP Content
Cato Cloud
  • network-alert
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Check Point Software

Product Event Types MITRE TTP Content
Check Point Identity Awareness
  • failed-vpn-login
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models
Check Point Security Gateway
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Cisco

Product Event Types MITRE TTP Content
AnyConnect
  • process-network
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models
Cisco Adaptive Security Appliance
  • authentication-failed
  • authentication-successful
  • dns-response
  • failed-logon
  • failed-vpn-login
  • file-download
  • file-upload
  • nac-logon
  • network-connection-successful
  • process-created
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-denied
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models
Cisco ISE
  • app-activity
  • authentication-failed
  • authentication-successful
  • computer-logon
  • failed-vpn-login
  • nac-failed-logon
  • nac-logon
  • remote-logon
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models
Cisco Meraki MX appliances
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models
Cisco Umbrella
  • config-change
  • dns-query
  • dns-response
  • failed-logon
  • network-connection-failed
  • network-connection-successful
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Citrix

Product Event Types MITRE TTP Content
Citrix Netscaler
  • app-activity
  • app-login
  • authentication-failed
  • failed-vpn-login
  • process-created
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models
Citrix Netscaler VPN
  • authentication-failed
  • authentication-successful
  • remote-access
  • remote-logon
  • vpn-connection
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Code42

Product Event Types MITRE TTP Content
Code42 Incydr
  • dlp-email-alert-out
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • print-activity
  • usb-activity
  • usb-insert
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: CrowdStrike

Product Event Types MITRE TTP Content
Falcon
  • app-activity
  • app-activity-failed
  • app-login
  • authentication-failed
  • batch-logon
  • computer-logon
  • config-change
  • dlp-alert
  • dns-query
  • failed-app-login
  • file-alert
  • file-delete
  • file-download
  • file-read
  • file-write
  • local-logon
  • network-connection-successful
  • process-alert
  • process-created
  • process-network
  • remote-access
  • remote-logon
  • security-alert
  • service-logon
  • task-created
  • usb-activity
  • usb-insert
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Dell

Product Event Types MITRE TTP Content
SonicWALL Aventail
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Digital Guardian

Product Event Types MITRE TTP Content
Digital Guardian Endpoint Protection
  • app-activity
  • dlp-email-alert-out
  • file-delete
  • file-download
  • file-read
  • file-upload
  • file-write
  • local-logon
  • print-activity
  • process-created
  • usb-insert
  • usb-write
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Dtex Systems

Product Event Types MITRE TTP Content
DTEX InTERCEPT
  • file-write
  • local-logon
  • print-activity
  • process-created
  • remote-logon
  • usb-write
  • web-activity-allowed
  • workstation-locked
  • workstation-unlocked
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: F5

Product Event Types MITRE TTP Content
F5 BIG-IP Access Policy Manager (APM)
  • authentication-failed
  • authentication-successful
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Forcepoint

Product Event Types MITRE TTP Content
Forcepoint DLP
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • usb-insert
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Fortinet

Product Event Types MITRE TTP Content
Fortinet VPN
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: InfoWatch

Product Event Types MITRE TTP Content
InfoWatch
  • app-login
  • dlp-email-alert-in
  • dlp-email-alert-out
  • print-activity
  • usb-write
  • web-activity-allowed
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Juniper Networks

Product Event Types MITRE TTP Content
Juniper SRX
  • account-deleted
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • network-alert
  • network-connection-failed
  • network-connection-successful
  • security-alert
  • vpn-connection
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models
Juniper VPN
  • account-deleted
  • authentication-failed
  • authentication-successful
  • failed-vpn-login
  • vpn-login
  • vpn-logout
  • web-activity-allowed
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Kaspersky

Product Event Types MITRE TTP Content
Kaspersky Endpoint Security for Business
  • dlp-alert
  • security-alert
  • usb-insert
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: LanScope

Product Event Types MITRE TTP Content
LanScope Cat
  • app-activity
  • dlp-alert
  • failed-usb-activity
  • local-logon
  • print-activity
  • usb-activity
  • usb-write
  • web-activity-allowed
  • workstation-locked
  • workstation-unlocked
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Lumension

Product Event Types MITRE TTP Content
Lumension
  • failed-usb-activity
  • usb-activity
  • usb-insert
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: McAfee

Product Event Types MITRE TTP Content
McAfee DLP
  • dlp-alert
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-usb-activity
  • print-activity
  • usb-write
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models
McAfee Endpoint Security
  • dlp-alert
  • failed-app-login
  • file-write
  • print-activity
  • process-alert
  • process-created-failed
  • remote-logon
  • security-alert
  • usb-insert
  • usb-write
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Microsoft

Product Event Types MITRE TTP Content
Microsoft Office 365
  • account-disabled
  • account-password-change
  • account-unlocked
  • app-activity
  • app-activity-failed
  • app-login
  • database-query
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • dns-query
  • failed-app-login
  • file-delete
  • file-download
  • file-permission-change
  • file-read
  • file-upload
  • file-write
  • member-added
  • member-removed
  • network-connection-failed
  • network-connection-successful
  • process-created
  • remote-logon
  • security-alert
  • usb-activity
  • usb-insert
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models
Microsoft Windows
  • account-creation
  • account-deleted
  • account-disabled
  • account-enabled
  • account-lockout
  • account-password-change
  • account-password-change-failed
  • account-password-reset
  • account-switch
  • account-unlocked
  • app-login
  • audit-log-clear
  • audit-policy-change
  • authentication-failed
  • authentication-successful
  • batch-logon
  • computer-logon
  • database-failed-login
  • database-query
  • dcom-activation-failed
  • dns-query
  • dns-response
  • ds-access
  • failed-app-login
  • failed-logon
  • failed-vpn-login
  • file-close
  • file-delete
  • file-read
  • file-write
  • kerberos-logon
  • local-logon
  • logout-remote
  • member-added
  • member-removed
  • nac-failed-logon
  • nac-logon
  • network-connection-successful
  • ntlm-logon
  • privileged-access
  • privileged-object-access
  • process-created
  • process-network
  • process-network-failed
  • registry-write
  • remote-access
  • remote-logon
  • security-alert
  • service-created
  • service-logon
  • share-access
  • share-access-denied
  • task-created
  • usb-activity
  • usb-insert
  • vpn-login
  • winsession-disconnect
  • workstation-locked
  • workstation-unlocked
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: NCP

Product Event Types MITRE TTP Content
NCP
  • authentication-failed
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: NetMotion Wireless

Product Event Types MITRE TTP Content
NetMotion Wireless
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Nortel Contivity

Product Event Types MITRE TTP Content
Nortel Contivity VPN
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Palo Alto Networks

Product Event Types MITRE TTP Content
GlobalProtect
  • app-activity
  • authentication-failed
  • authentication-successful
  • config-change
  • failed-logon
  • failed-vpn-login
  • remote-logon
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: RSA

Product Event Types MITRE TTP Content
SecurID
  • authentication-failed
  • authentication-successful
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: SSL Open VPN

Product Event Types MITRE TTP Content
SSL Open VPN
  • app-activity
  • app-activity-failed
  • authentication-failed
  • failed-vpn-login
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Safend

Product Event Types MITRE TTP Content
Data Protection Suite (DPS)
  • dlp-alert
  • usb-insert
  • usb-read
  • usb-write
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: SecureNet

Product Event Types MITRE TTP Content
SecureNet
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Sonicwall

Product Event Types MITRE TTP Content
Sonicwall
  • failed-vpn-login
  • network-alert
  • remote-logon
  • vpn-login
  • vpn-logout
  • web-activity-allowed
  • web-activity-denied
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models

Vendor: Sophos

Product Event Types MITRE TTP Content
Sophos Endpoint Protection
  • dlp-alert
  • failed-usb-activity
  • failed-vpn-login
  • file-alert
  • network-alert
  • network-connection-failed
  • security-alert
  • usb-insert
  • usb-write
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 7 Rules
  • 4 Models

Vendor: Symantec

Product Event Types MITRE TTP Content
Symantec DLP
  • config-change
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-in-failed
  • dlp-email-alert-out
  • dlp-email-alert-out-failed
  • failed-logon
  • failed-usb-activity
  • file-alert
  • file-delete
  • file-write
  • member-added
  • member-removed
  • network-alert
  • process-alert
  • security-alert
  • usb-insert
  • usb-read
  • usb-write
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Trend Micro

Product Event Types MITRE TTP Content
OfficeScan
  • dlp-alert
  • dlp-email-alert-in
  • dlp-email-alert-out
  • privileged-object-access
  • security-alert
  • usb-write
  • web-activity-allowed
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: VMware

Product Event Types MITRE TTP Content
VMware Carbon Black App Control
  • app-login
  • file-alert
  • file-delete
  • file-download
  • file-read
  • file-write
  • local-logon
  • network-connection-failed
  • network-connection-successful
  • process-alert
  • process-created
  • process-network
  • security-alert
  • usb-insert
  • workstation-locked
  • workstation-unlocked
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 6 Rules
  • 3 Models

Vendor: Zscaler

Product Event Types MITRE TTP Content
Zscaler Private Access
  • vpn-login
  • vpn-logout
T1052.001 - Exfiltration Over Physical Medium: Exfiltration over USB
  • 1 Rules
  • 1 Models