Splunk non-Windows coverage

814 non-Windows Splunk detection rules across 13 platforms, grouped by MITRE ATT&CK technique within each platform. The Windows coverage matrix lives at /rules/splunk/; this page reorganizes the same corpus along platform × technique because non-Windows rules have no catalog event IDs to plot.

For coverage organized by each platform's native action vocabulary across all vendors, see the platform matrices: AWS, Azure AD, GCP, M365, Okta. This page is the vendor-organized browse of the same rules.

Platform (all)
Domain (all)

Linux

Reconnaissance

Gather Victim Identity Information: Credentials T1589.001 1 rule

Initial Access

Exploit Public-Facing Application T1190 2 rules
Hardware Additions T1200 2 rules

Execution

Scheduled Task/Job: Cron T1053.003 8 rules
Command and Scripting Interpreter: Unix Shell T1059.004 5 rules
Scheduled Task/Job: Systemd Timers T1053.006 4 rules
Scheduled Task/Job: At T1053.002 3 rules
Command and Scripting Interpreter T1059 1 rule
Command and Scripting Interpreter: Container CLI/API T1059.013 1 rule
System Services: Service Execution T1569.002 1 rule

Persistence

Boot or Logon Autostart Execution: Kernel Modules and Extensions T1547.006 7 rules
Account Manipulation: SSH Authorized Keys T1098.004 4 rules
Create Account: Local Account T1136.001 4 rules
Account Manipulation T1098 2 rules
Boot or Logon Initialization Scripts: RC Scripts T1037.004 1 rule
External Remote Services T1133 1 rule
Server Software Component: vSphere Installation Bundles T1505.006 1 rule
Create or Modify System Process: Launch Agent T1543.001 1 rule

Privilege Escalation

Abuse Elevation Control Mechanism: Sudo and Sudo Caching T1548.003 35 rules
Exploitation for Privilege Escalation T1068 5 rules
Abuse Elevation Control Mechanism: Setuid and Setgid T1548.001 5 rules
Event Triggered Execution: Unix Shell Configuration Modification T1546.004 3 rules
Abuse Elevation Control Mechanism T1548 2 rules
Escape to Host T1611 1 rule

Stealth

Indicator Removal: File Deletion T1070.004 8 rules
Valid Accounts T1078 4 rules
Rootkit T1014 3 rules
Hijack Execution Flow: Dynamic Linker Hijacking T1574.006 3 rules
Obfuscated Files or Information T1027 2 rules
Indicator Removal T1070 2 rules
Masquerading: Masquerade Task or Service T1036.004 1 rule
Indicator Removal: Timestomp T1070.006 1 rule
Valid Accounts: Local Accounts T1078.003 1 rule
Deobfuscate/Decode Files or Information T1140 1 rule
Execution Guardrails T1480 1 rule

Defense Impairment

Disable or Modify Tools T1685 6 rules
File and Directory Permissions Modification: Linux and Mac Permissions T1222.002 4 rules
Disable or Modify System Firewall T1686 4 rules
Disable or Modify Tools: Disable or Modify Linux Audit System Log T1685.004 3 rules
Prevent Command History Logging T1690 2 rules
Modify System Image: Patch System Image T1601.001 1 rule

Credential Access

Brute Force T1110 10 rules
OS Credential Dumping: /etc/passwd and /etc/shadow T1003.008 3 rules
Unsecured Credentials: Private Keys T1552.004 2 rules
Credentials from Password Stores: Password Managers T1555.005 2 rules
Unsecured Credentials: Credentials In Files T1552.001 1 rule

Discovery

File and Directory Discovery T1083 4 rules
System Information Discovery T1082 3 rules
System Network Configuration Discovery T1016 2 rules
Virtual Machine Discovery T1673 2 rules
System Owner/User Discovery T1033 1 rule

Lateral Movement

Remote Services: SSH T1021.004 2 rules
Remote Services T1021 1 rule

Collection

Data from Local System T1005 2 rules
Clipboard Data T1115 2 rules

Command & Control

Ingress Tool Transfer T1105 3 rules
Proxy T1090 2 rules
Non-Application Layer Protocol T1095 1 rule
Web Service T1102 1 rule
Protocol Tunneling T1572 1 rule

Exfiltration

Data Transfer Size Limits T1030 2 rules
Exfiltration Over Web Service T1567 1 rule

Impact

Data Destruction T1485 14 rules
Service Stop T1489 7 rules
System Shutdown/Reboot T1529 3 rules
Endpoint Denial of Service T1499 2 rules

Untagged

macOS

Execution

Command and Scripting Interpreter T1059 1 rule
Command and Scripting Interpreter: AppleScript T1059.002 1 rule
Command and Scripting Interpreter: Unix Shell T1059.004 1 rule

Persistence

Account Manipulation T1098 2 rules
Boot or Logon Initialization Scripts: Login Hook T1037.002 1 rule
Create Account T1136 1 rule
Create Account: Local Account T1136.001 1 rule
Server Software Component: vSphere Installation Bundles T1505.006 1 rule
Create or Modify System Process T1543 1 rule
Create or Modify System Process: Launch Agent T1543.001 1 rule

Stealth

Valid Accounts T1078 4 rules
Indicator Removal T1070 2 rules
Indicator Removal: Timestomp T1070.006 1 rule
Hide Artifacts: Hidden Files and Directories T1564.001 1 rule

Defense Impairment

Disable or Modify Tools T1685 5 rules
Prevent Command History Logging T1690 2 rules
Subvert Trust Controls: Gatekeeper Bypass T1553.001 1 rule
Modify System Image: Patch System Image T1601.001 1 rule
Plist File Modification T1647 1 rule
Disable or Modify System Firewall T1686 1 rule

Credential Access

Brute Force T1110 10 rules
OS Credential Dumping: /etc/passwd and /etc/shadow T1003.008 1 rule
Credentials from Password Stores: Keychain T1555.001 1 rule

Discovery

Virtual Machine Discovery T1673 2 rules
System Network Configuration Discovery T1016 1 rule
System Information Discovery T1082 1 rule
Network Share Discovery T1135 1 rule

Lateral Movement

Remote Services T1021 1 rule
Remote Services: SSH T1021.004 1 rule

Collection

Data from Local System T1005 2 rules

Exfiltration

Data Transfer Size Limits T1030 1 rule

Impact

Endpoint Denial of Service T1499 1 rule
System Shutdown/Reboot T1529 1 rule

Untagged

AWS

Resource Development

Compromise Accounts: Cloud Accounts T1586.003 15 rules
Compromise Accounts T1586 1 rule

Initial Access

Phishing: Spearphishing Attachment T1566.001 4 rules
Phishing T1566 2 rules

Execution

User Execution T1204 15 rules
User Execution: Malicious Image T1204.003 8 rules

Persistence

Create Account: Cloud Account T1136.003 7 rules
Account Manipulation T1098 6 rules
Compromise Host Software Binary T1554 2 rules
Account Manipulation: Additional Cloud Credentials T1098.001 1 rule
Account Manipulation: Additional Email Delegate Permissions T1098.002 1 rule

Stealth

Valid Accounts T1078 9 rules
Valid Accounts: Cloud Accounts T1078.004 7 rules
Unused/Unsupported Cloud Regions T1535 5 rules
Hide Artifacts: Email Hiding Rules T1564.008 1 rule

Defense Impairment

Disable or Modify Tools: Disable or Modify Cloud Log T1685.002 14 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 4 rules
Disable or Modify System Firewall: Cloud Firewall T1686.001 4 rules
Modify Cloud Compute Infrastructure: Create Cloud Instance T1578.002 1 rule
Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations T1578.005 1 rule

Credential Access

Brute Force T1110 5 rules
Multi-Factor Authentication Request Generation T1621 4 rules
Brute Force: Password Guessing T1110.001 3 rules
Brute Force: Password Spraying T1110.003 3 rules
Brute Force: Credential Stuffing T1110.004 3 rules
Exploitation for Credential Access T1212 2 rules
Steal Application Access Token T1528 1 rule
Unsecured Credentials T1552 1 rule

Discovery

Cloud Service Discovery T1526 5 rules
Cloud Infrastructure Discovery T1580 5 rules
Network Service Discovery T1046 3 rules
Permission Groups Discovery: Cloud Groups T1069.003 2 rules
Password Policy Discovery T1201 2 rules

Lateral Movement

Use Alternate Authentication Material T1550 1 rule

Collection

Data from Cloud Storage T1530 6 rules
Email Collection: Email Forwarding Rule T1114.003 3 rules
Automated Collection T1119 3 rules
Email Collection T1114 2 rules
Email Collection: Remote Email Collection T1114.002 2 rules
Browser Session Hijacking T1185 2 rules

Exfiltration

Transfer Data to Cloud Account T1537 6 rules
Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 1 rule
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule

Impact

Data Encrypted for Impact T1486 3 rules
Data Destruction T1485 2 rules
Data Destruction: Lifecycle-Triggered Deletion T1485.001 2 rules
Inhibit System Recovery T1490 2 rules

Untagged

Azure

Resource Development

Compromise Accounts: Cloud Accounts T1586.003 9 rules

Initial Access

Phishing: Spearphishing Attachment T1566.001 4 rules
Phishing T1566 2 rules
Phishing: Spearphishing Link T1566.002 1 rule

Execution

User Execution T1204 14 rules
Software Deployment Tools T1072 4 rules
User Execution: Malicious Image T1204.003 1 rule

Persistence

Account Manipulation: Additional Cloud Roles T1098.003 10 rules
Create Account: Cloud Account T1136.003 8 rules
Account Manipulation T1098 3 rules
Account Manipulation: Additional Cloud Credentials T1098.001 2 rules
Account Manipulation: Additional Email Delegate Permissions T1098.002 2 rules
Compromise Host Software Binary T1554 2 rules
Account Manipulation: Device Registration T1098.005 1 rule

Stealth

Valid Accounts: Cloud Accounts T1078.004 7 rules
Valid Accounts T1078 2 rules
Indirect Command Execution T1202 2 rules
Hide Artifacts: Email Hiding Rules T1564.008 1 rule

Defense Impairment

Domain or Tenant Policy Modification: Trust Modification T1484.002 2 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 2 rules
Disable or Modify Tools T1685 2 rules
Domain or Tenant Policy Modification T1484 1 rule
Disable or Modify System Firewall T1686 1 rule

Credential Access

Brute Force: Password Spraying T1110.003 7 rules
Steal Application Access Token T1528 5 rules
Brute Force: Password Guessing T1110.001 3 rules
Brute Force: Credential Stuffing T1110.004 3 rules
Multi-Factor Authentication Request Generation T1621 3 rules
OS Credential Dumping: Security Account Manager T1003.002 2 rules
Exploitation for Credential Access T1212 2 rules
Brute Force T1110 1 rule

Discovery

Cloud Service Discovery T1526 6 rules
Account Discovery: Cloud Account T1087.004 2 rules

Lateral Movement

Remote Services: Cloud Services T1021.007 4 rules

Collection

Email Collection: Email Forwarding Rule T1114.003 3 rules
Data from Cloud Storage T1530 3 rules
Email Collection T1114 2 rules
Email Collection: Remote Email Collection T1114.002 2 rules
Browser Session Hijacking T1185 1 rule

Command & Control

Ingress Tool Transfer T1105 2 rules

Exfiltration

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 1 rule
Transfer Data to Cloud Account T1537 1 rule
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule

Impact

System Shutdown/Reboot T1529 1 rule
Disk Wipe: Disk Content Wipe T1561.001 1 rule

Untagged

GCP

Initial Access

Phishing: Spearphishing Attachment T1566.001 4 rules
Phishing T1566 2 rules

Execution

User Execution T1204 14 rules
User Execution: Malicious Image T1204.003 1 rule

Persistence

Create Account: Cloud Account T1136.003 2 rules
Compromise Host Software Binary T1554 2 rules
Account Manipulation: Additional Cloud Credentials T1098.001 1 rule
Account Manipulation: Additional Email Delegate Permissions T1098.002 1 rule

Stealth

Valid Accounts T1078 1 rule
Valid Accounts: Cloud Accounts T1078.004 1 rule
Hide Artifacts: Email Hiding Rules T1564.008 1 rule

Credential Access

Exploitation for Credential Access T1212 2 rules
Brute Force T1110 1 rule
Steal Application Access Token T1528 1 rule

Discovery

Cloud Service Discovery T1526 4 rules

Collection

Email Collection: Email Forwarding Rule T1114.003 3 rules
Data from Cloud Storage T1530 3 rules
Email Collection T1114 2 rules
Email Collection: Remote Email Collection T1114.002 2 rules

Exfiltration

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 1 rule
Transfer Data to Cloud Account T1537 1 rule
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule

Untagged

Microsoft 365

Resource Development

Compromise Accounts: Cloud Accounts T1586.003 2 rules

Initial Access

Phishing: Spearphishing Attachment T1566.001 5 rules
Phishing: Spearphishing Link T1566.002 4 rules

Execution

User Execution: Malicious File T1204.002 2 rules

Persistence

Account Manipulation: Additional Cloud Roles T1098.003 9 rules
Create Account: Cloud Account T1136.003 6 rules
Account Manipulation: Additional Email Delegate Permissions T1098.002 4 rules
Account Manipulation T1098 1 rule
Account Manipulation: Device Registration T1098.005 1 rule

Stealth

Indicator Removal: Clear Mailbox Data T1070.008 6 rules
Hide Artifacts: Email Hiding Rules T1564.008 2 rules
Valid Accounts T1078 1 rule

Defense Impairment

Modify Authentication Process T1556 2 rules
Disable or Modify Tools: Disable or Modify Cloud Log T1685.002 2 rules
Domain or Tenant Policy Modification: Trust Modification T1484.002 1 rule
Disable or Modify Tools T1685 1 rule
Disable or Modify System Firewall: Cloud Firewall T1686.001 1 rule

Credential Access

Steal Application Access Token T1528 3 rules
Brute Force: Password Guessing T1110.001 2 rules
Brute Force: Password Spraying T1110.003 2 rules
Brute Force: Credential Stuffing T1110.004 2 rules
Unsecured Credentials T1552 2 rules
OS Credential Dumping: Security Account Manager T1003.002 1 rule
Brute Force T1110 1 rule
Multi-Factor Authentication Request Generation T1621 1 rule

Collection

Email Collection: Remote Email Collection T1114.002 7 rules
Email Collection: Local Email Collection T1114.001 4 rules
Email Collection: Email Forwarding Rule T1114.003 3 rules
Data from Cloud Storage T1530 3 rules
Browser Session Hijacking T1185 1 rule
Data from Information Repositories: Sharepoint T1213.002 1 rule

Exfiltration

Exfiltration Over Web Service T1567 5 rules
Exfiltration Over Alternative Protocol T1048 1 rule

Impact

Data Destruction T1485 6 rules

Google Workspace

Resource Development

Compromise Accounts: Cloud Accounts T1586.003 6 rules

Stealth

Valid Accounts: Cloud Accounts T1078.004 3 rules

Defense Impairment

Modify Authentication Process: Multi-Factor Authentication T1556.006 1 rule

Credential Access

Brute Force: Password Spraying T1110.003 2 rules
Brute Force: Credential Stuffing T1110.004 2 rules
Multi-Factor Authentication Request Generation T1621 2 rules

Okta

Resource Development

Compromise Accounts: Cloud Accounts T1586.003 3 rules

Persistence

Account Manipulation: Device Registration T1098.005 1 rule

Stealth

Valid Accounts T1078 3 rules
Valid Accounts: Default Accounts T1078.001 3 rules
Valid Accounts: Cloud Accounts T1078.004 3 rules

Defense Impairment

Modify Authentication Process T1556 1 rule
Modify Authentication Process: Multi-Factor Authentication T1556.006 1 rule

Credential Access

Multi-Factor Authentication Request Generation T1621 4 rules
Brute Force T1110 3 rules
Brute Force: Password Spraying T1110.003 1 rule
Steal Web Session Cookie T1539 1 rule

Discovery

Account Discovery: Cloud Account T1087.004 2 rules
Cloud Service Dashboard T1538 1 rule

Lateral Movement

Use Alternate Authentication Material: Web Session Cookie T1550.004 1 rule

Command & Control

Proxy T1090 1 rule
Protocol Tunneling T1572 1 rule

GitHub

Initial Access

Supply Chain Compromise T1195 18 rules

Defense Impairment

Disable or Modify Tools T1685 10 rules
Disable or Modify Tools: Disable or Modify Cloud Log T1685.002 3 rules

Impact

Data Destruction T1485 5 rules

Kubernetes

Execution

User Execution T1204 7 rules
Scheduled Task/Job: Container Orchestration Job T1053.007 1 rule

Credential Access

Unsecured Credentials: Container API T1552.007 4 rules

Discovery

Network Service Discovery T1046 2 rules
Cloud Service Discovery T1526 1 rule

Untagged

Network

Reconnaissance

Active Scanning: Vulnerability Scanning T1595.002 4 rules
Gather Victim Network Information: IP Addresses T1590.005 2 rules
Active Scanning T1595 2 rules
Gather Victim Network Information T1590 1 rule
Gather Victim Network Information: Domain Properties T1590.001 1 rule
Phishing for Information T1598 1 rule

Resource Development

Acquire Infrastructure: Web Services T1583.006 1 rule
Develop Capabilities: Malware T1587.001 1 rule
Develop Capabilities: Code Signing Certificates T1587.002 1 rule
Obtain Capabilities: Tool T1588.002 1 rule
Obtain Capabilities: Digital Certificates T1588.004 1 rule

Initial Access

Exploit Public-Facing Application T1190 54 rules
Hardware Additions T1200 5 rules

Execution

Command and Scripting Interpreter T1059 12 rules
Exploitation for Client Execution T1203 9 rules
Scheduled Task/Job: Cron T1053.003 2 rules
Command and Scripting Interpreter: PowerShell T1059.001 2 rules
Command and Scripting Interpreter: Visual Basic T1059.005 2 rules
User Execution: Malicious Image T1204.003 2 rules
Scheduled Task/Job: Container Orchestration Job T1053.007 1 rule
User Execution T1204 1 rule
User Execution: Malicious File T1204.002 1 rule

Persistence

External Remote Services T1133 11 rules
Server Software Component: Web Shell T1505.003 4 rules
Create Account T1136 3 rules
Create or Modify System Process T1543 3 rules
Account Manipulation T1098 2 rules
Create Account: Local Account T1136.001 1 rule
Server Software Component T1505 1 rule

Privilege Escalation

Exploitation for Privilege Escalation T1068 3 rules
Escape to Host T1611 2 rules

Stealth

Valid Accounts T1078 6 rules
Obfuscated Files or Information T1027 3 rules
Process Injection T1055 3 rules
Valid Accounts: Local Accounts T1078.003 2 rules
BITS Jobs T1197 2 rules
System Binary Proxy Execution: Mshta T1218.005 2 rules
Impair Defenses T1562 2 rules
Masquerading T1036 1 rule
Indicator Removal T1070 1 rule
Indicator Removal: Clear Windows Event Logs T1070.001 1 rule
Indicator Removal: Clear Mailbox Data T1070.008 1 rule
System Binary Proxy Execution T1218 1 rule
XSL Script Processing T1220 1 rule
Pre-OS Boot: TFTP Boot T1542.005 1 rule

Defense Impairment

Modify Authentication Process T1556 15 rules
Disable or Modify Tools T1685 5 rules
Rogue Domain Controller T1207 2 rules
Modify Authentication Process: Network Device Authentication T1556.004 1 rule
Disable or Modify Tools: Disable or Modify Windows Event Log T1685.001 1 rule

Credential Access

Adversary-in-the-Middle: ARP Cache Poisoning T1557.002 3 rules
Network Sniffing T1040 2 rules
Brute Force T1110 2 rules
Unsecured Credentials T1552 2 rules
Adversary-in-the-Middle T1557 2 rules
OS Credential Dumping T1003 1 rule
OS Credential Dumping: LSASS Memory T1003.001 1 rule
OS Credential Dumping: DCSync T1003.006 1 rule
Brute Force: Password Guessing T1110.001 1 rule
Brute Force: Password Spraying T1110.003 1 rule
Unsecured Credentials: Cloud Instance Metadata API T1552.005 1 rule

Discovery

Network Service Discovery T1046 7 rules
Remote System Discovery T1018 3 rules
System Network Configuration Discovery T1016 2 rules
System Information Discovery T1082 2 rules

Lateral Movement

Remote Services: SSH T1021.004 5 rules
Exploitation of Remote Services T1210 4 rules
Remote Services T1021 3 rules
Remote Services: Remote Desktop Protocol T1021.001 1 rule
Remote Services: SMB/Windows Admin Shares T1021.002 1 rule

Collection

Data from Local System T1005 3 rules
Email Collection: Remote Email Collection T1114.002 1 rule
Data from Cloud Storage T1530 1 rule

Command & Control

Ingress Tool Transfer T1105 12 rules
Application Layer Protocol: Web Protocols T1071.001 11 rules
Remote Access Tools T1219 5 rules
Encrypted Channel: Asymmetric Cryptography T1573.002 5 rules
Non-Standard Port T1571 3 rules
Application Layer Protocol T1071 2 rules
Proxy: Multi-hop Proxy T1090.003 2 rules
Encrypted Channel T1573 2 rules
Application Layer Protocol: File Transfer Protocols T1071.002 1 rule
Application Layer Protocol: DNS T1071.004 1 rule
Proxy T1090 1 rule
Proxy: External Proxy T1090.002 1 rule
Non-Application Layer Protocol T1095 1 rule
Protocol Tunneling T1572 1 rule

Exfiltration

Exfiltration Over C2 Channel T1041 7 rules
Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 3 rules
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 3 rules
Automated Exfiltration: Traffic Duplication T1020.001 1 rule
Exfiltration Over Alternative Protocol T1048 1 rule
Exfiltration Over Web Service T1567 1 rule

Impact

Network Denial of Service T1498 5 rules
Network Denial of Service: Reflection Amplification T1498.002 1 rule
Endpoint Denial of Service T1499 1 rule
Account Access Removal T1531 1 rule

Untagged

Web

Reconnaissance

Active Scanning T1595 1 rule

Initial Access

Exploit Public-Facing Application T1190 23 rules
Phishing T1566 12 rules

Execution

Command and Scripting Interpreter: PowerShell T1059.001 1 rule
Command and Scripting Interpreter: Windows Command Shell T1059.003 1 rule

Persistence

External Remote Services T1133 12 rules
Server Software Component: Web Shell T1505.003 6 rules

Credential Access

Brute Force: Password Guessing T1110.001 1 rule
Brute Force: Credential Stuffing T1110.004 1 rule

Discovery

System Information Discovery T1082 1 rule

Command & Control

Application Layer Protocol: Web Protocols T1071.001 2 rules

Exfiltration

Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 2 rules
Exfiltration Over Web Service T1567 1 rule

Untagged

Application

Reconnaissance

Active Scanning T1595 1 rule

Initial Access

Exploit Public-Facing Application T1190 5 rules
Phishing: Spearphishing Attachment T1566.001 2 rules

Execution

Command and Scripting Interpreter T1059 3 rules

Persistence

Account Manipulation: Device Registration T1098.005 2 rules

Stealth

Valid Accounts T1078 4 rules
Masquerading: Masquerade File Type T1036.008 1 rule

Defense Impairment

Disable or Modify Tools T1685 5 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 2 rules

Credential Access

Multi-Factor Authentication Request Generation T1621 3 rules
Brute Force T1110 2 rules
Unsecured Credentials: Credentials In Files T1552.001 2 rules
Credentials from Password Stores T1555 1 rule

Collection

Audio Capture T1123 3 rules
Email Collection: Remote Email Collection T1114.002 1 rule

Command & Control

Non-Standard Port T1571 1 rule

Exfiltration

Exfiltration Over Alternative Protocol T1048 1 rule

Impact

Service Stop T1489 1 rule
Network Denial of Service T1498 1 rule
Endpoint Denial of Service T1499 1 rule

Untagged