Skip to content

Latest commit

 

History

History
24 lines (22 loc) · 5.28 KB

ds_jsonar_sonarg.md

File metadata and controls

24 lines (22 loc) · 5.28 KB

Vendor: jSONAR

Product: SonarG

Rules Models MITRE TTPs Event Types Parsers
41 19 7 1 1
Use-Case Event Types/Parsers MITRE TTP Content
Abnormal Authentication & Access local-logon
jsonar-database-login
T1078 - Valid Accounts
T1078.003 - Valid Accounts: Local Accounts
  • 24 Rules
  • 9 Models
Brute Force Attack local-logon
jsonar-database-login
T1078 - Valid Accounts
  • 1 Rules
  • 1 Models
Compromised Credentials local-logon
jsonar-database-login
T1078.002 - T1078.002
T1558 - Steal or Forge Kerberos Tickets
  • 4 Rules
  • 2 Models
Lateral Movement local-logon
jsonar-database-login
T1558 - Steal or Forge Kerberos Tickets
  • 1 Rules
Malware local-logon
jsonar-database-login
T1204 - User Execution
  • 2 Rules
  • 2 Models
Privilege Abuse local-logon
jsonar-database-login
T1078 - Valid Accounts
T1078.002 - T1078.002
  • 10 Rules
  • 6 Models
Privilege Escalation local-logon
jsonar-database-login
T1021.002 - Remote Services: SMB/Windows Admin Shares
T1078 - Valid Accounts
T1087 - Account Discovery
  • 3 Rules
  • 3 Models
Privileged Activity local-logon
jsonar-database-login
T1078 - Valid Accounts
  • 6 Rules
  • 3 Models

ATT&CK Matrix for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
Valid Accounts

User Execution

Valid Accounts

Valid Accounts

Valid Accounts

Valid Accounts: Local Accounts

Steal or Forge Kerberos Tickets

Account Discovery

Remote Services

Remote Services: SMB/Windows Admin Shares