109 indexed

ATT&CKATT&CK data components

109 MITRE ATT&CK data components — the specific signals within a data source used to detect techniques. Use /search for keyword lookup. Authored by Adam Lundqvist.

Showing 101–109 of 109 · page 3 of 3

IDTitleSummary
Volume MetadataVolume MetadataContextual data about a cloud volume and activity around it, such as id, type, state, and size
Volume ModificationVolume ModificationChanges made to a cloud volume, including its settings and control data (ex: AWS modify-volume)
Web Credential CreationWeb Credential CreationInitial construction of new web credential material (ex: Windows EID 1200 or 4769)
Web Credential UsageWeb Credential UsageAn attempt by a user to gain access to a network or computing resource by providing web credentials (ex: Windows EID 1202)
Windows Registry Key AccessWindows Registry Key AccessOpening a Registry Key, typically to read the associated value (ex: Windows EID 4656)
Windows Registry Key CreationWindows Registry Key CreationInitial construction of a new Registry Key (ex: Windows EID 4656 or Sysmon EID 12)
Windows Registry Key DeletionWindows Registry Key DeletionRemoval of a Registry Key (ex: Windows EID 4658 or Sysmon EID 12)
Windows Registry Key ModificationWindows Registry Key ModificationChanges made to a Registry Key and/or Key value (ex: Windows EID 4657 or Sysmon EID 13|14)
WMI CreationWMI CreationInitial construction of a WMI object, such as a filter, consumer, subscription, binding, or provider (ex: Sysmon EIDs 19-21)
Sourced from MITRE ATT&CK Data Components. Curated by Adam Lundqvist, Founder at SQUR.