Skip to content

Latest commit

 

History

History
22 lines (20 loc) · 13.9 KB

ds_sap_sap.md

File metadata and controls

22 lines (20 loc) · 13.9 KB

Vendor: SAP

Product: SAP

Rules Models MITRE ATT&CK® TTPs Activity Types Parsers
174 70 29 12 12
Use-Case Activity Types/Parsers MITRE ATT&CK® TTP Content
Abnormal Authentication & Access account-creation
sap-s-cef-user-create-success-created

account-deleted
sap-s-cef-user-delete-success-deleted

account-lockout
sap-s-cef-user-lock-success-locked

account-password-change
sap-s-cef-user-password-modify-success-changed
sap-s-cef-user-password-modify-success-loginforsso

account-unlocked
sap-s-cef-user-unlock-success-unlocked

app-login
sap-s-kv-network-session-functioncall
sap-s-cef-network-session-rfccallsuccess
sap-s-cef-app-login-success-dialoglogonsuccessful

authentication-failed
sap-s-cef-endpoint-login-fail-secude

authentication-successful
sap-s-cef-endpoint-login-success-assertion-1
sap-s-cef-endpoint-login-success-assertion

failed-app-login
sap-s-cef-app-login-fail-dialoglogonfailed

remote-logon
sap-s-cef-app-logout-userlogoff
sap-s-cef-app-notification-success-attribute
sap-s-cef-app-notification-accessbyrfc
sap-s-cef-app-notification-success-cbus
sap-s-cef-app-notification-transactionstarted
sap-s-cef-app-notification-success-bul
sap-s-cef-app-notification-transactionfailed
sap-s-cef-app-notification-success-nameid
sap-s-cef-app-notification-reportstarted
sap-s-cef-app-notification-success-bu4
sap-s-cef-app-notification-messagecu1
sap-s-cef-app-notification-success-e00
sap-s-cef-app-notification-success-h01
sap-s-cef-app-notification-success-bi0
sap-s-cef-app-notification-success-duz
sap-s-cef-app-notification-success-eg0
sap-s-cef-app-notification-success-cub
sap-s-cef-app-notification-success-aud
sap-s-cef-app-notification-success-geo
sap-s-cef-endpoint-login-fail-cpiclogonfail
sap-s-cef-endpoint-login-success-cpiclogonsuccessful
T1021 - Remote Services
T1078 - Valid Accounts
T1078.002 - T1078.002
T1078.003 - Valid Accounts: Local Accounts
T1110 - Brute Force
T1133 - External Remote Services
  • 36 Rules
  • 14 Models
Account Manipulation account-creation
sap-s-cef-user-create-success-created

account-deleted
sap-s-cef-user-delete-success-deleted

account-password-change
sap-s-cef-user-password-modify-success-changed
sap-s-cef-user-password-modify-success-loginforsso
T1098 - Account Manipulation
T1136 - Create Account
T1136.001 - Create Account: Create: Local Account
T1136.002 - T1136.002
T1531 - Account Access Removal
  • 22 Rules
  • 8 Models
Brute Force Attack account-lockout
sap-s-cef-user-lock-success-locked
T1110 - Brute Force
  • 1 Rules
Data Exfiltration file-write
sap-s-cef-file-write-success-download
TA0002 - TA0002
  • 2 Rules
  • 1 Models
Data Leak file-write
sap-s-cef-file-write-success-download
T1114.001 - T1114.001
  • 1 Rules
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact
External Remote Services

Valid Accounts

Exploit Public Fasing Application

Create Account

External Remote Services

Valid Accounts

Server Software Component: Web Shell

Account Manipulation

Server Software Component

Boot or Logon Autostart Execution

Create Account: Create: Local Account

Valid Accounts

Exploitation for Privilege Escalation

Boot or Logon Autostart Execution

Valid Accounts

Use Alternate Authentication Material

Use Alternate Authentication Material: Pass the Hash

Use Alternate Authentication Material: Pass the Ticket

Valid Accounts: Local Accounts

OS Credential Dumping

Brute Force

Steal or Forge Kerberos Tickets

Credentials from Password Stores

Steal or Forge Kerberos Tickets: Kerberoasting

File and Directory Discovery

Remote System Discovery

Remote Services

Use Alternate Authentication Material

Email Collection

Proxy: Multi-hop Proxy

Proxy

Account Access Removal

Data Encrypted for Impact