Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Lateral Movement/ T1210

T1210Exploitation of Remote Services

T1210 — Exploitation of Remote Services is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 14 detection use cases covering it and 1 threat-intel article citing it.

Lateral Movement
View on the matrix → Filter Detection Library MITRE official spec ↗
14Use cases
1Articles
0Sub-techniques
1Tactic

Use cases covering this technique (14)

Splunk RCE Through Arbitrary File Write to Windows System Root ESCU actions · hunting P Splunk RCE via User XSLT ESCU actions · hunting P Splunk App for Lookup File Editing RCE via User XSLT ESCU actions · hunting P Splunk Code Injection via custom dashboard leading to RCE ESCU actions · hunting P Splunk RCE PDFgen Render ESCU actions · alerting P Active Directory Lateral Movement Identified ESCU actions · alerting P Detect Computer Changed with Anonymous Account ESCU actions · hunting P Cisco Secure Firewall - Lumma Stealer Activity ESCU actions · alerting P Cisco Secure Firewall - Static Tundra Smart Install Abuse ESCU actions · alerting P Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity ESCU actions · alerting P VMWare Aria Operations Exploit Attempt ESCU actions · alerting P Splunk RCE via External Lookup Copybuckets ESCU actions · hunting P Splunk RCE via Splunk Secure Gateway Splunk Mobile alerts feature ESCU actions · hunting P [LLM] Web/interpreter process connecting to internal HiveServer2 (10000) or Hadoop NameNode (50070) Bespoke exploit · alerting DSΣPCS

Articles citing this technique (1)