Skip to content

Latest commit

 

History

History
12 lines (10 loc) · 1.5 KB

r_m_bitdefender_gravityzone_Data_Exfiltration.md

File metadata and controls

12 lines (10 loc) · 1.5 KB

Vendor: Bitdefender

Product: GravityZone

Rules Models MITRE ATT&CK® TTPs Event Types Parsers
6 2 4 1 1
Event Type Rules Models
web-activity-denied T1071.001 - Application Layer Protocol: Web Protocols
A-WEB-DynamicDNS: Asset attempted access to a domain generated using Dynamic DNS service
WEB-New-File-20-Block: User with no web activity history was blocked from uploading 20MB or more

T1567.002 - Exfiltration Over Web Service: Exfiltration to Cloud Storage
WEB-FS: User has accessed a file sharing domain
WEB-OU-FS: One of the top file sharing users in the organization
WEB-OG-FS: One of the top file sharing users in the peer group

T1568.002 - Dynamic Resolution: Domain Generation Algorithms
WEB-UD-DynamicDNS: User attempted access to a domain generated using Dynamic DNS service

T1568 - Dynamic Resolution
A-WEB-DynamicDNS: Asset attempted access to a domain generated using Dynamic DNS service
WEB-OG-FS: File sharing activities of users in the peer group
WEB-OU-FS: File sharing activities of users in the organization