About 50 results
Open links in new tab
  1. Logon Session Creation, Data Component DC0067 | MITRE ATT&CK®

    Dec 28, 2024 · The successful establishment of a new user session following a successful authentication attempt. This typically signifies that a user has provided valid credentials or …

  2. Network Traffic Flow, Data Component DC0078 | MITRE ATT&CK®

    Oct 20, 2021 · Summarized network packet data that captures session-level details such as source/destination IPs, ports, protocol types, timestamps, and data volume, without storing full …

  3. Firewall Rule Modification, Data Component DC0051 | MITRE ATT&CK®

    The creation, deletion, or alteration of firewall rules to allow or block specific network traffic. Monitoring changes to these rules is critical for detecting misconfigurations, unauthorized access, or malicious …

  4. Network Traffic Content, Data Component DC0085 | MITRE ATT&CK®

    The full packet capture (PCAP) or session data that logs both protocol headers and payload content. This allows analysts to inspect command and control (C2) traffic, exfiltration, and other suspicious …

  5. Service Creation, Data Component DC0060 | MITRE ATT&CK®

    The registration of a new service or daemon on an operating system. Data Collection Measures: Windows Event Logs Event ID 4697 - Captures the creation of a new Windows service. Event ID …

  6. Response Metadata, Data Component DC0106 | MITRE ATT&CK®

    Contextual information about an Internet-facing resource collected during a scan, including details such as open ports, running services, protocols, and versions. This metadata is typically derived from …

  7. Web Credential Creation, Data Component DC0006 | MITRE ATT&CK®

    Oct 20, 2021 · Initial construction of new web credential material (ex: Windows EID 1200 or 4769)

  8. Network Communication, Data Component DC0113 | MITRE ATT&CK®

    Mar 13, 2023 · Network requests made by an application or domains contacted ID: DC0113

  9. Malware Metadata, Data Component DC0003 | MITRE ATT&CK®

    Oct 20, 2021 · Contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information

  10. WMI Creation, Data Component DC0008 | MITRE ATT&CK®

    Oct 20, 2021 · Initial construction of a WMI object, such as a filter, consumer, subscription, binding, or providers.