atomic-threat-coverage/analytics.csv
2018-12-12 06:19:57 +01:00

28 KiB

1tactictechniquetitlefielddn_PLATFORMdn_TYPEdn_channeldn_event_idlogging_policy_title
2TA0008: Lateral Movementattack.t1078Admin User Remote LogonEventIDWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
3TA0008: Lateral Movementattack.t1078Admin User Remote LogonEventIDWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
4TA0008: Lateral Movementattack.t1078Admin User Remote LogonEventIDWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
5TA0008: Lateral Movementattack.t1078Admin User Remote LogonEventIDWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
6TA0008: Lateral Movementattack.t1078Admin User Remote LogonAccountNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
7TA0008: Lateral Movementattack.t1078Admin User Remote LogonAccountNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
8TA0008: Lateral Movementattack.t1078Admin User Remote LogonAccountNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
9TA0008: Lateral Movementattack.t1078Admin User Remote LogonAccountNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
10TA0008: Lateral Movementattack.t1078Admin User Remote LogonHostnameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
11TA0008: Lateral Movementattack.t1078Admin User Remote LogonHostnameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
12TA0008: Lateral Movementattack.t1078Admin User Remote LogonHostnameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
13TA0008: Lateral Movementattack.t1078Admin User Remote LogonHostnameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
14TA0008: Lateral Movementattack.t1078Admin User Remote LogonComputerWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
15TA0008: Lateral Movementattack.t1078Admin User Remote LogonComputerWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
16TA0008: Lateral Movementattack.t1078Admin User Remote LogonComputerWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
17TA0008: Lateral Movementattack.t1078Admin User Remote LogonComputerWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
18TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectUserSidWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
19TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectUserSidWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
20TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectUserSidWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
21TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectUserSidWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
22TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectUserNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
23TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectUserNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
24TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectUserNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
25TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectUserNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
26TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectDomainNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
27TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectDomainNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
28TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectDomainNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
29TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectDomainNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
30TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectLogonIdWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
31TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectLogonIdWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
32TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectLogonIdWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
33TA0008: Lateral Movementattack.t1078Admin User Remote LogonSubjectLogonIdWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
34TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetUserSidWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
35TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetUserSidWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
36TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetUserSidWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
37TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetUserSidWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
38TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetUserNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
39TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetUserNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
40TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetUserNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
41TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetUserNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
42TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetDomainNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
43TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetDomainNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
44TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetDomainNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
45TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetDomainNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
46TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetLogonIdWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
47TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetLogonIdWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
48TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetLogonIdWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
49TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetLogonIdWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
50TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonTypeWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
51TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonTypeWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
52TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonTypeWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
53TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonTypeWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
54TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonProcessNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
55TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonProcessNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
56TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonProcessNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
57TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonProcessNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
58TA0008: Lateral Movementattack.t1078Admin User Remote LogonAuthenticationPackageNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
59TA0008: Lateral Movementattack.t1078Admin User Remote LogonAuthenticationPackageNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
60TA0008: Lateral Movementattack.t1078Admin User Remote LogonAuthenticationPackageNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
61TA0008: Lateral Movementattack.t1078Admin User Remote LogonAuthenticationPackageNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
62TA0008: Lateral Movementattack.t1078Admin User Remote LogonWorkstationNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
63TA0008: Lateral Movementattack.t1078Admin User Remote LogonWorkstationNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
64TA0008: Lateral Movementattack.t1078Admin User Remote LogonWorkstationNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
65TA0008: Lateral Movementattack.t1078Admin User Remote LogonWorkstationNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
66TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonGuidWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
67TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonGuidWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
68TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonGuidWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
69TA0008: Lateral Movementattack.t1078Admin User Remote LogonLogonGuidWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
70TA0008: Lateral Movementattack.t1078Admin User Remote LogonTransmittedServicesWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
71TA0008: Lateral Movementattack.t1078Admin User Remote LogonTransmittedServicesWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
72TA0008: Lateral Movementattack.t1078Admin User Remote LogonTransmittedServicesWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
73TA0008: Lateral Movementattack.t1078Admin User Remote LogonTransmittedServicesWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
74TA0008: Lateral Movementattack.t1078Admin User Remote LogonLmPackageNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
75TA0008: Lateral Movementattack.t1078Admin User Remote LogonLmPackageNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
76TA0008: Lateral Movementattack.t1078Admin User Remote LogonLmPackageNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
77TA0008: Lateral Movementattack.t1078Admin User Remote LogonLmPackageNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
78TA0008: Lateral Movementattack.t1078Admin User Remote LogonKeyLengthWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
79TA0008: Lateral Movementattack.t1078Admin User Remote LogonKeyLengthWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
80TA0008: Lateral Movementattack.t1078Admin User Remote LogonKeyLengthWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
81TA0008: Lateral Movementattack.t1078Admin User Remote LogonKeyLengthWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
82TA0008: Lateral Movementattack.t1078Admin User Remote LogonProcessIdWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
83TA0008: Lateral Movementattack.t1078Admin User Remote LogonProcessIdWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
84TA0008: Lateral Movementattack.t1078Admin User Remote LogonProcessIdWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
85TA0008: Lateral Movementattack.t1078Admin User Remote LogonProcessIdWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
86TA0008: Lateral Movementattack.t1078Admin User Remote LogonProcessNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
87TA0008: Lateral Movementattack.t1078Admin User Remote LogonProcessNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
88TA0008: Lateral Movementattack.t1078Admin User Remote LogonProcessNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
89TA0008: Lateral Movementattack.t1078Admin User Remote LogonProcessNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
90TA0008: Lateral Movementattack.t1078Admin User Remote LogonIpAddressWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
91TA0008: Lateral Movementattack.t1078Admin User Remote LogonIpAddressWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
92TA0008: Lateral Movementattack.t1078Admin User Remote LogonIpAddressWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
93TA0008: Lateral Movementattack.t1078Admin User Remote LogonIpAddressWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
94TA0008: Lateral Movementattack.t1078Admin User Remote LogonIpPortWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
95TA0008: Lateral Movementattack.t1078Admin User Remote LogonIpPortWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
96TA0008: Lateral Movementattack.t1078Admin User Remote LogonIpPortWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
97TA0008: Lateral Movementattack.t1078Admin User Remote LogonIpPortWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
98TA0008: Lateral Movementattack.t1078Admin User Remote LogonImpersonationLevelWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
99TA0008: Lateral Movementattack.t1078Admin User Remote LogonImpersonationLevelWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
100TA0008: Lateral Movementattack.t1078Admin User Remote LogonImpersonationLevelWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
101TA0008: Lateral Movementattack.t1078Admin User Remote LogonImpersonationLevelWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
102TA0008: Lateral Movementattack.t1078Admin User Remote LogonRestrictedAdminModeWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
103TA0008: Lateral Movementattack.t1078Admin User Remote LogonRestrictedAdminModeWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
104TA0008: Lateral Movementattack.t1078Admin User Remote LogonRestrictedAdminModeWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
105TA0008: Lateral Movementattack.t1078Admin User Remote LogonRestrictedAdminModeWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
106TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetOutboundUserNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
107TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetOutboundUserNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
108TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetOutboundUserNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
109TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetOutboundUserNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
110TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetOutboundDomainNameWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
111TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetOutboundDomainNameWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
112TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetOutboundDomainNameWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
113TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetOutboundDomainNameWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
114TA0008: Lateral Movementattack.t1078Admin User Remote LogonVirtualAccountWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
115TA0008: Lateral Movementattack.t1078Admin User Remote LogonVirtualAccountWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
116TA0008: Lateral Movementattack.t1078Admin User Remote LogonVirtualAccountWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
117TA0008: Lateral Movementattack.t1078Admin User Remote LogonVirtualAccountWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
118TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetLinkedLogonIdWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
119TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetLinkedLogonIdWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
120TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetLinkedLogonIdWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
121TA0008: Lateral Movementattack.t1078Admin User Remote LogonTargetLinkedLogonIdWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
122TA0008: Lateral Movementattack.t1078Admin User Remote LogonElevatedTokenWindowsWindows LogSecurity4624LP_0004_windows_audit_logon
123TA0008: Lateral Movementattack.t1078Admin User Remote LogonElevatedTokenWindowsWindows LogSecurity4625LP_0004_windows_audit_logon
124TA0008: Lateral Movementattack.t1078Admin User Remote LogonElevatedTokenWindowsWindows LogSecurity4648LP_0004_windows_audit_logon
125TA0008: Lateral Movementattack.t1078Admin User Remote LogonElevatedTokenWindowsWindows LogSecurity4675LP_0004_windows_audit_logon
126TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsEventIDWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
127TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsHostnameWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
128TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsUsernameWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
129TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessGuidWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
130TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessIdWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
131TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessNameWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
132TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsCommandLineWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
133TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsLogonGuidWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
134TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsLogonIdWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
135TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsTerminalSessionidWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
136TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsIntegrityLevelWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
137TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsImphashWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
138TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsSha256hashWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
139TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsSha1hashWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
140TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsMd5hashWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
141TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessGuidWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
142TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessIdWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
143TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessNameWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
144TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentCommandLineWindowsWindows LogMicrosoft-Windows-Sysmon/Operational4688LP_0002_windows_audit_process_creation_with_commandline
145TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsEventIDWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
146TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsHostnameWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
147TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsUsernameWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
148TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsUserSidWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
149TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessPidWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
150TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessNameWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
151TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsNewProcessNameWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
152TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsImageWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
153TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsCommandLineWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
154TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessCommandLineWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
155TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcesssCommandLineWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
156TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessPidWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
157TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessNameWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
158TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsMandatoryLabelWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
159TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsTokenElevationTypeWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
160TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsLogonIdWindowsWindows LogSecurity4688LP_0002_windows_audit_process_creation_with_commandline
161TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsEventIDWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
162TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsHostnameWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
163TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsUsernameWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
164TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessGuidWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
165TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessIdWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
166TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessNameWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
167TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsCommandLineWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
168TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsLogonGuidWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
169TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsLogonIdWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
170TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsTerminalSessionidWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
171TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsIntegrityLevelWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
172TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsImphashWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
173TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsSha256hashWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
174TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsSha1hashWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
175TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsMd5hashWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
176TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessGuidWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
177TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessIdWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
178TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessNameWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
179TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentCommandLineWindowsWindows LogMicrosoft-Windows-Sysmon/Operational-1-
180TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsEventIDWindowsWindows LogSecurity-1-
181TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsHostnameWindowsWindows LogSecurity-1-
182TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsUsernameWindowsWindows LogSecurity-1-
183TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsUserSidWindowsWindows LogSecurity-1-
184TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessPidWindowsWindows LogSecurity-1-
185TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessNameWindowsWindows LogSecurity-1-
186TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsNewProcessNameWindowsWindows LogSecurity-1-
187TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsImageWindowsWindows LogSecurity-1-
188TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsCommandLineWindowsWindows LogSecurity-1-
189TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcessCommandLineWindowsWindows LogSecurity-1-
190TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsProcesssCommandLineWindowsWindows LogSecurity-1-
191TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessPidWindowsWindows LogSecurity-1-
192TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsParentProcessNameWindowsWindows LogSecurity-1-
193TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsMandatoryLabelWindowsWindows LogSecurity-1-
194TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsTokenElevationTypeWindowsWindows LogSecurity-1-
195TA0005: Defense Evasionattack.t1036Suspicious Process Start LocationsLogonIdWindowsWindows LogSecurity-1-