Input Capture T1417

Mobile Tactics: Collection, Credential Access

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (5 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType1eq 1SMISHING_ALERT
SmishingAlertSeverity1in 1CRITICAL, HIGH
SmishingAlertType1in 1CREDENTIAL_HARVESTING, FRAUD_DETECTION, PHISHING_DETECTION
entries1is_not_null 1
result_type1eq 1maliciousness

Top indicator values (7 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
SMISHING_ALERT
1
SmishingAlertSeverityin
CRITICAL
1
SmishingAlertSeverityin
HIGH
1
SmishingAlertTypein
CREDENTIAL_HARVESTING
1
SmishingAlertTypein
FRAUD_DETECTION
1
SmishingAlertTypein
PHISHING_DETECTION
1
result_typeeq
maliciousness
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Application

Domain: Application

Kusto 2 rules