mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge pull request #1716 from splunk/CARS_UPDATE_MITRE_ID_B1
Cars update mitre id b1
This commit is contained in:
@@ -44,6 +44,7 @@ tags:
|
||||
of $expected_upper_threshold$ with the following command $command$.
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
nist:
|
||||
- DE.DP
|
||||
- DE.CM
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
command $command$.
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
nist:
|
||||
- DE.DP
|
||||
- DE.CM
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
in their account
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -43,6 +43,7 @@ tags:
|
||||
from this IP $src$
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
and did a console login from this IP $src_ip$
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -37,6 +37,7 @@ tags:
|
||||
message: Vulnerabilities with severity high found in image $image$
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
message: Vulnerabilities with severity high found in repository $repositoryName$
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -35,6 +35,7 @@ tags:
|
||||
message: Vulnerabilities with severity high found in image $image$
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
message: Container uploaded outside business hours from $user$
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
message: Container uploaded from unknown user $user$
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -42,6 +42,7 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1069.003
|
||||
- T1098
|
||||
- T1069
|
||||
observable:
|
||||
- name: src
|
||||
type: IP Address
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
CIDR $requestParameters.cidrBlock$
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
nist:
|
||||
- DE.DP
|
||||
- DE.AE
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
$eventName$), such that the instance is accessible from anywhere
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
nist:
|
||||
- DE.DP
|
||||
- DE.AE
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
event $eventName$ for updating the the default policy version
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
user $user_arn$ more access privilleges
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
message: User $user$ is creating a new instance $dest$ for the first time
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
nist:
|
||||
- ID.AM
|
||||
observable:
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
message: User $user$ is modifying an instance $dest$ for the first time.
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
nist:
|
||||
- ID.AM
|
||||
observable:
|
||||
|
||||
@@ -27,6 +27,7 @@ tags:
|
||||
message: Correlation triggered for user $user$
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -27,6 +27,7 @@ tags:
|
||||
message: Correlation triggered for user $user$
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
message: Vulnerabilities found in packages used by GitHub repository $repository$
|
||||
mitre_attack_id:
|
||||
- T1195.001
|
||||
- T1195
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
message: Vulnerabilities found in packages used by GitHub repository $repository$
|
||||
mitre_attack_id:
|
||||
- T1195.001
|
||||
- T1195
|
||||
nist:
|
||||
- PR.DS
|
||||
- PR.AC
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
message: suspicious share gdrive from $parameters.owner$ to $email$ namely as $parameters.doc_title$
|
||||
mitre_attack_id:
|
||||
- T1567.002
|
||||
- T1567
|
||||
observable:
|
||||
- name: parameters.owner
|
||||
type: User
|
||||
@@ -66,3 +67,4 @@ tags:
|
||||
- parameters.doc_type
|
||||
risk_score: 72
|
||||
security_domain: endpoint
|
||||
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
message: suspicious email from $source.address$ to $destination{}.address$
|
||||
mitre_attack_id:
|
||||
- T1566.001
|
||||
- T1566
|
||||
observable:
|
||||
- name: source.address
|
||||
type: User
|
||||
|
||||
@@ -49,6 +49,7 @@ tags:
|
||||
message: suspicious email from $source.address$ to $destination{}.address$
|
||||
mitre_attack_id:
|
||||
- T1566.001
|
||||
- T1566
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
message: suspicious email from $source.address$ to $destination{}.address$
|
||||
mitre_attack_id:
|
||||
- T1566.001
|
||||
- T1566
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -40,6 +40,7 @@ tags:
|
||||
message: suspicious email from $source.address$ to $destination{}.address$
|
||||
mitre_attack_id:
|
||||
- T1048.003
|
||||
- T1048
|
||||
observable:
|
||||
- name: source.address
|
||||
type: User
|
||||
|
||||
@@ -46,6 +46,7 @@ tags:
|
||||
message: suspicious share gdrive from $parameters.owner$ to $email$ namely as $parameters.doc_title$
|
||||
mitre_attack_id:
|
||||
- T1566.001
|
||||
- T1566
|
||||
observable:
|
||||
- name: parameters.owner
|
||||
type: User
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
Address $ActorIpAddress$
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
observable:
|
||||
- name: ActorIpAddress
|
||||
type: IP Address
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
service principal credentials from IP Address $ActorIpAddress$
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
observable:
|
||||
- name: ActorIpAddress
|
||||
type: IP Address
|
||||
|
||||
@@ -45,6 +45,7 @@ tags:
|
||||
list of trusted IPs to bypass MFA
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
observable:
|
||||
- name: ip_addresses_new_added
|
||||
type: IP Address
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
$OrganizationName$
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
observable:
|
||||
- name: OrganizationName
|
||||
type: Other
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
the same destination $ForwardingAddress$
|
||||
mitre_attack_id:
|
||||
- T1114.003
|
||||
- T1114
|
||||
nist:
|
||||
- DE.DP
|
||||
- DE.AE
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
that allow access to sensitive
|
||||
mitre_attack_id:
|
||||
- T1114.002
|
||||
- T1114
|
||||
nist:
|
||||
- DE.DP
|
||||
- DE.AE
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
a forwarding rule to same destination $ForwardingSmtpAddress$
|
||||
mitre_attack_id:
|
||||
- T1114.003
|
||||
- T1114
|
||||
nist:
|
||||
- DE.DP
|
||||
- DE.AE
|
||||
|
||||
Reference in New Issue
Block a user