+Audit

Audit

Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures. Auditing is applicable to all systems used within an organization, from the front door of a building to accessing a file on a fileserver. It is considered more critical for regulated industries such as, healthcare, finance and government where compliance requirements demand stringent tracking of user and system activates.This mitigation can be implemented through the following measures: System Audit: - Use Case: Regularly assess system configurations to ensure compliance with organizational security policies. - Implementation: Use tools to scan for deviations from established benchmarks. Permission Audits: - Use Case: Review file and folder permissions to minimize the risk of unauthorized access or privilege escalation. - Implementation: Run access reviews to identify users or groups with excessive permissions. Software Audits: - Use Case: Identify outdated, unsupported, or insecure software that could serve as an attack vector. - Implementation: Use inventory and vulnerability scanning tools to detect outdated versions and recommend secure alternatives. Configuration Audits: - Use Case: Evaluate system and network configurations to ensure secure settings (e.g., disabled SMBv1, enabled MFA). - Implementation: Implement automated configuration scanning tools like SCAP (Security Content Automation Protocol) to identify non-compliant systems. Network Audits: - Use Case: Examine network traffic, firewall rules, and endpoint communications to identify unauthorized or insecure connections. - Implementation: Utilize tools such as Wireshark, or Zeek to monitor and log suspicious network behavior.

1. Übersicht

Bezeichnung Standard

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Regulations

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Regulations

Regulations
Source Regulierung

Linked Issues

Issuelinks
Linktyp Issue
is related to Mitigations
blocks Domain or Tenant Policy Modification
blocks Python
blocks Masquerading
blocks Domain Trust Discovery
blocks Cron
blocks Executable Installer File Permissions Weakness
blocks Terminal Services DLL
blocks Cloud Firewall
blocks Browser Extensions
blocks Server Software Component
blocks Pre-OS Boot
blocks Phishing
blocks Group Policy Modification
blocks Steal Web Session Cookie
blocks SQL Stored Procedures
blocks Run Virtual Instance
blocks Disable or Modify System Firewall
blocks Network Device Firewall
blocks Path Interception by Unquoted Path
blocks Disable or Modify Windows Event Log
blocks Remote Desktop Protocol
blocks Email Hiding Rules
blocks Bypass User Account Control
blocks AS-REP Roasting
blocks Fileless Storage
blocks At
blocks Windows Service
blocks Cloud Application Integration
blocks Use Alternate Authentication Material
blocks Group Policy Preferences
blocks Disable or Modify Tools
blocks Steal Application Access Token
blocks Hijack Execution Flow
blocks Deploy Container
blocks Web Cookies
blocks Confluence
blocks Messaging Applications
blocks Spearphishing Link
blocks LC_LOAD_DYLIB Addition
blocks Hide Artifacts
blocks Create or Modify System Process
blocks Ccache Files
blocks Sharepoint
blocks Network Provider DLL
blocks RDP Hijacking
blocks Remote Services
blocks Create Snapshot
blocks VNC
blocks IDE Extensions
blocks Chat Messages
blocks Spearphishing Attachment
blocks Clear Mailbox Data
blocks Lua
blocks Application Access Token
blocks Social Engineering
blocks SAML Tokens
blocks Non-Application Layer Protocol
blocks Cloud Account
blocks Multi-Factor Authentication
blocks Modify Cloud Compute Infrastructure
blocks Archive via Utility
blocks Abuse Elevation Control Mechanism
blocks Browser Fingerprint
blocks Code Repositories
blocks Disable or Modify Linux Audit System Log
blocks Modify Cloud Compute Configurations
blocks Spearphishing via Service
blocks Credentials in Registry
blocks Scheduled Task/Job
blocks Services File Permissions Weakness
blocks Archive Collected Data
blocks Obfuscated Files or Information
blocks IIS Components
blocks Software Extensions
blocks Customer Relationship Management Software
blocks Hybrid Identity
blocks Unsecured Credentials
blocks Create Cloud Instance
blocks Path Interception by Search Order Hijacking
blocks ROMMONkit
blocks Scheduled Task
blocks DLL
blocks Malicious Image
blocks Delete Cloud Instance
blocks Build Image on Host
blocks Transport Agent
blocks Command and Scripting Interpreter
blocks Power Settings
blocks Modify Cloud Resource Hierarchy
blocks Path Interception by PATH Environment Variable
blocks Masquerade Account Name
blocks Email Forwarding Rule
blocks Steal or Forge Authentication Certificates
blocks Email Collection
blocks Forge Web Credentials
blocks Credentials In Files
blocks TCC Manipulation
blocks Data from Cloud Storage
blocks Launch Daemon
blocks Search Open Websites/Domains
blocks Data from Information Repositories
blocks Private Keys
blocks TFTP Boot
blocks Modify Authentication Process
blocks Steal or Forge Kerberos Tickets
blocks Windows Host Firewall
blocks Implant Internal Image
blocks Databases
blocks vSphere Installation Bundles
blocks Code Repositories
  • MITREATTACK -

    © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. https://attack.mitre.org/

    Terms of Use

    LICENSE

    The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

    "© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation."

    DISCLAIMERS

    MITRE does not claim ATT&CK enumerates all possibilities for the types of actions and behaviors documented as part of its adversary model and framework of techniques. Using the information contained within ATT&CK to address or cover full categories of techniques will not guarantee full defensive coverage as there may be undisclosed techniques or variations on existing techniques not documented by ATT&CK.

    ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

    See our FAQ for more information on how to use and represent the ATT&CK name.

Impressum Deutsch Englisch