Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Lateral Movement/ T1210

T1210Exploitation of Remote Services

T1210 — Exploitation of Remote Services is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 15 detection use cases covering it and 1 threat-intel article citing it.

Lateral Movement
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
1Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

Splunk RCE Through Arbitrary File Write to Windows System Root ESCU actions · hunting P Splunk RCE via User XSLT ESCU actions · hunting P Active Directory Lateral Movement Identified ESCU actions · alerting P Detect Computer Changed with Anonymous Account ESCU actions · hunting P Linux Suspicious Redis Activity ESCU actions · alerting P Cisco Secure Firewall - Lumma Stealer Activity ESCU actions · alerting P Cisco Secure Firewall - Static Tundra Smart Install Abuse ESCU actions · alerting P Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity ESCU actions · alerting P VMWare Aria Operations Exploit Attempt ESCU actions · alerting P Splunk App for Lookup File Editing RCE via User XSLT ESCU actions · hunting P Splunk Code Injection via custom dashboard leading to RCE ESCU actions · hunting P Splunk RCE PDFgen Render ESCU actions · alerting P Splunk RCE via External Lookup Copybuckets ESCU actions · hunting P Splunk RCE via Splunk Secure Gateway Splunk Mobile alerts feature ESCU actions · hunting P [LLM] One host fanning out to multiple internal Ray dashboards (8265/10001) Bespoke exploit · hunting DSPDDCSCW

Articles citing this technique (1)