mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
refactor(02-01): remove prose em dashes from YAML and Markdown files
- clickfix-techniques.yml: fix 10 em dashes in Notes, Detections, and References Name fields; cut weak closer from Description; quote YAML Name values with colons - edr-bypass-techniques.yml: fix 7 em dashes in Context and References/Variation Name fields; quote YAML Name values with colons - remote-execution-tools.yml: fix 5 em dashes in References Name fields; quote YAML Name values - trends/clickgrab.md: fix 15 em dashes in titles, prose paragraphs, and callouts; preserve Liquid empty-cell placeholders - trends/index.md: fix 5 em dashes in hero text, pillar descriptions, and front matter description - trends/masq-infra.md: fix 5 em dashes in front matter, methodology, and chokepoints prose; preserve 7 Liquid table placeholder instances
This commit is contained in:
@@ -277,21 +277,21 @@ Detections:
|
||||
UseCase: SOC alerting for active lateral movement; direct IR escalation trigger
|
||||
SigmaRule: sigma-rules/remote-execution/analyst.yml
|
||||
Intel:
|
||||
- Name: MITRE ATT&CK — Impacket Software S0357
|
||||
- Name: 'MITRE ATT&CK: Impacket Software S0357'
|
||||
Tier: primary
|
||||
URL: https://attack.mitre.org/software/S0357/
|
||||
Description: Lists every known threat actor (APT groups, ransomware operators) documented using Impacket; far more useful
|
||||
to a defender than the raw GitHub repo for understanding real-world prevalence
|
||||
- Name: MITRE ATT&CK — T1021.003 DCOM
|
||||
- Name: 'MITRE ATT&CK: T1021.003 DCOM'
|
||||
Tier: primary
|
||||
URL: https://attack.mitre.org/techniques/T1021/003/
|
||||
Description: Technique definition for DCOM-based lateral movement; covers dcomexec.py usage and detection guidance
|
||||
- Name: MITRE ATT&CK — T1569.002 Service Execution
|
||||
- Name: 'MITRE ATT&CK: T1569.002 Service Execution'
|
||||
Tier: primary
|
||||
URL: https://attack.mitre.org/techniques/T1569/002/
|
||||
Description: Technique definition for service-based remote execution (psexec/smbexec pattern); the primary detection signal
|
||||
in this chokepoint's hunt and analyst rules
|
||||
- Name: Microsoft — Storm-0501 Ransomware Hybrid Cloud Attacks
|
||||
- Name: 'Microsoft: Storm-0501 Ransomware Hybrid Cloud Attacks'
|
||||
Tier: primary
|
||||
URL: https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
|
||||
Description: Documents Storm-0501 using Impacket SecretsDump for lateral movement in hybrid cloud environments; concrete
|
||||
@@ -307,7 +307,7 @@ Intel:
|
||||
Tier: primary
|
||||
URL: https://github.com/Pennyw0rth/NetExec
|
||||
Description: Active successor to CrackMapExec; track new protocol support and OPSEC improvements that affect detection
|
||||
- Name: SOC Investigation — Event ID 5145 Threat Hunting
|
||||
- Name: 'SOC Investigation: Event ID 5145 Threat Hunting'
|
||||
Tier: primary
|
||||
URL: https://www.socinvestigation.com/threat-hunting-with-eventid-5145-object-access-detailed-file-share/
|
||||
Description: Detailed guidance on using Event ID 5145 (Detailed File Share) for lateral movement detection; covers IPC$
|
||||
|
||||
Reference in New Issue
Block a user