Detecttechnique
D3-UBAUser Behavior Analysis
User Behavior Analysis
Definition
Defends against95
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Technique | Encrypted Channelt1573 | 100% | live |
| SubTechnique | Spearphishing Linkt1566.002 | 100% | live |
| SubTechnique | Exfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002 | 100% | live |
| Technique | Forge Web Credentialst1606 | 100% | live |
| Technique | Drive-by Compromiset1189 | 100% | live |
| SubTechnique | Domain Frontingt1090.004 | 100% | live |
| SubTechnique | Windows Management Instrumentation Event Subscriptiont1546.003 | 100% | live |
| Technique | Scheduled Transfert1029 | 100% | live |
| SubTechnique | Make and Impersonate Tokent1134.003 | 100% | live |
| SubTechnique | LLMNR/NBT-NS Poisoning and SMB Relayt1557.001 | 100% | live |
| SubTechnique | Additional Cloud Credentialst1098.001 | 100% | live |
| SubTechnique | Domain Accountt1087.002 | 100% | live |
| SubTechnique | Password Crackingt1110.002 | 100% | live |
| Technique | Exfiltration Over C2 Channelt1041 | 100% | live |
| Technique | Exfiltration Over Web Servicet1567 | 100% | live |
| SubTechnique | Application Access Tokent1550.001 | 100% | live |
| Technique | Rogue Domain Controllert1207 | 100% | live |
| SubTechnique | Credential Stuffingt1110.004 | 100% | live |
| Technique | Steal or Forge Kerberos Ticketst1558 | 100% | live |
| Technique | Unsecured Credentialst1552 | 100% | live |
| SubTechnique | Local Accountt1087.001 | 100% | live |
| SubTechnique | Direct Network Floodt1498.001 | 100% | live |
| Technique | Automated Exfiltrationt1020 | 100% | live |
| SubTechnique | Exfiltration Over Unencrypted Non-C2 Protocolt1048.003 | 100% | live |
| SubTechnique | External Proxyt1090.002 | 100% | live |
| SubTechnique | Multi-hop Proxyt1090.003 | 100% | live |
| Technique | Traffic Signalingt1205 | 100% | live |
| Technique | Adversary-in-the-Middlet1557 | 100% | live |
| Technique | Browser Session Hijackingt1185 | 100% | live |
| Technique | Non-Application Layer Protocolt1095 | 100% | live |
Showing top 30 of 95 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.