Center for Threat-Informed Defense

Version 15.1 16.0

Data Sources : Enterprise ATT&CK Changelog

Modified Data Sources

Description

A profile representing a user, device, service, or application used to authenticate and access resources

Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-12-07T19:50:43.993Z 2024-10-14T22:11:30.271Z
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Office Suite
x_mitre_platforms Identity Provider
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Azure AD
x_mitre_platforms Google Workspace
x_mitre_platforms Office 365

Description

Credential material, such as session cookies or tokens, used to authenticate to web applications and services[1][2]

References:

  1. Hsu, S. (2018, June 30). Session vs Token Based Authentication. Retrieved September 29, 2021.
  2. Auth0. (n.d.). Access Tokens. Retrieved September 29, 2021.
Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-03-30T14:26:51.807Z 2024-10-14T22:11:30.271Z
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Office Suite
x_mitre_platforms Identity Provider
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Azure AD
x_mitre_platforms Google Workspace
x_mitre_platforms Office 365

Description

Events collected by third-party services such as mail servers, web applications, or other appliances (not by the native OS or platform)[1]

References:

  1. Confluence Support. (2021, April 22). Working with Confluence Logs. Retrieved September 23, 2021.
Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-05-11T14:00:00.188Z 2024-10-14T22:11:30.271Z
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Office Suite
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Google Workspace
x_mitre_platforms Office 365

Description

A network security system, running locally on an endpoint or remotely as a service (ex: cloud environment), that monitors and controls incoming/outgoing network traffic based on predefined rules[1]

References:

  1. Amazon. (n.d.). Security groups for your VPC. Retrieved October 13, 2021.
Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-03-30T14:26:51.805Z 2024-10-14T22:11:30.271Z
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Office Suite
x_mitre_platforms Identity Provider
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Azure AD
x_mitre_platforms Google Workspace
x_mitre_platforms Office 365

Description

Infrastructure, platforms, or software that are hosted on-premise or by third-party providers, made available to users through network connections and/or APIs[1][2]

References:

  1. Amazon. (n.d.). Start Building on AWS Today. Retrieved October 13, 2021.
  2. Microsoft. (n.d.). Azure products. Retrieved October 13, 2021.
Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-03-30T14:26:51.804Z 2024-10-14T22:11:30.271Z
x_mitre_platforms[3] Office 365 Identity Provider
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Office Suite
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Azure AD
x_mitre_platforms Google Workspace

Description

A database and set of services that allows administrators to manage permissions, access to network resources, and stored data objects (user, group, application, or devices)[1]

References:

  1. Foulds, I. et al. (2018, August 7). AD DS Getting Started. Retrieved September 23, 2021.
Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-03-30T14:26:51.803Z 2024-10-14T22:11:30.271Z
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Identity Provider
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Azure AD

Description

Logon occurring on a system or resource (local, domain, or cloud) to which a user/device is gaining access after successful authentication and authorization[1]

References:

  1. Microsoft. (2021, September 6). Audit logon events. Retrieved September 28, 2021.
Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-12-07T19:45:09.019Z 2024-10-14T22:11:30.271Z
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Office Suite
x_mitre_platforms Identity Provider
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Azure AD
x_mitre_platforms Google Workspace
x_mitre_platforms Office 365

Description

A collection of multiple user accounts that share the same access rights to the computer and/or network resources and have common security rights[1]

References:

  1. Amazon. (n.d.). IAM user groups. Retrieved October 13, 2021.
Details
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2022-03-30T14:26:51.805Z 2024-10-14T22:11:30.271Z
x_mitre_platforms[3] Office 365 Office Suite
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Identity Provider
Iterable Item Removed
FIELD OLD VALUE NEW VALUE
x_mitre_platforms Azure AD
x_mitre_platforms Google Workspace