Skip to content

Latest commit

 

History

History
12 lines (10 loc) · 830 Bytes

r_m_mcafee_mdam_Data_Exfiltration.md

File metadata and controls

12 lines (10 loc) · 830 Bytes

Vendor: McAfee

Product: MDAM

Rules Models MITRE ATT&CK® TTPs Event Types Parsers
2 1 1 1 1
Event Type Rules Models
database-alert TA0002 - TA0002
DB-TEMP-DIRECTORY-F: First time process has been executed from a temporary directory by this user during database activity
DB-TEMP-DIRECTORY-A: Abnormal process has been executed from a temporary directory by this user during database activity
DB-UP-TEMP: Process executable TEMP directories for this user during database activity