Skip to content

Latest commit

 

History

History
12 lines (10 loc) · 848 Bytes

r_m_microsoft_applocker_Lateral_Movement.md

File metadata and controls

12 lines (10 loc) · 848 Bytes

Vendor: Microsoft

Product: AppLocker

Rules Models MITRE ATT&CK® TTPs Event Types Parsers
4 0 1 1 1
Event Type Rules Models
security-alert T1027.005 - Obfuscated Files or Information: Indicator Removal from Tools
A-ALERT-DL: DL Correlation rule alert on asset
A-ALERT-Correlation-Rule: Correlation rule alert on asset
ALERT-Correlation-Rule: Correlation rule alert on asset accessed by this user
ALERT-DL: DL Correlation rule alert on asset accessed by this user