diff --git a/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml b/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml index b16e060915..5b075f2a2a 100644 --- a/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml +++ b/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml @@ -33,6 +33,7 @@ tags: analytic_story: - Cobalt Strike - NOBELIUM Group + cis20: [] confidence: 60 context: - Source:Endpoint @@ -48,6 +49,7 @@ tags: mitre_attack_id: - T1560.001 - T1560 + nist: [] observable: - name: user type: User diff --git a/detections/endpoint/ssa___detect_rclone_command_line_usage.yml b/detections/endpoint/ssa___detect_rclone_command_line_usage.yml index 6e6f9dfd95..b07427d0d3 100644 --- a/detections/endpoint/ssa___detect_rclone_command_line_usage.yml +++ b/detections/endpoint/ssa___detect_rclone_command_line_usage.yml @@ -45,6 +45,7 @@ tags: - DarkSide Ransomware - Ransomware automated_detection_testing: passed + cis20: [] confidence: 70 context: - Source:Endpoint @@ -59,6 +60,7 @@ tags: remote cloud service to move files or folders. mitre_attack_id: - T1020 + nist: [] observable: - name: dest_user_id type: User diff --git a/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml b/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml index 08e143cb3b..1f063339aa 100644 --- a/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml +++ b/detections/endpoint/ssa___dns_exfiltration_using_nslookup_app.yml @@ -42,6 +42,7 @@ tags: - Command and Control - Data Exfiltration automated_detection_testing: passed + cis20: [] confidence: 80 context: - Source:Endpoint @@ -56,6 +57,7 @@ tags: to DNS exfiltration. mitre_attack_id: - T1048 + nist: [] observable: - name: dest_user_id type: User diff --git a/detections/endpoint/ssa___fsutil_zeroing_file.yml b/detections/endpoint/ssa___fsutil_zeroing_file.yml index eac803137a..921fd6fa62 100644 --- a/detections/endpoint/ssa___fsutil_zeroing_file.yml +++ b/detections/endpoint/ssa___fsutil_zeroing_file.yml @@ -33,6 +33,7 @@ references: tags: analytic_story: - Ransomware + cis20: [] confidence: 90 context: - Source:Endpoint @@ -50,6 +51,7 @@ tags: nist: - PR.AC - PR.IP + nist: [] observable: - name: dest_user_id type: User diff --git a/detections/endpoint/ssa___sdelete_application_execution.yml b/detections/endpoint/ssa___sdelete_application_execution.yml index f9538df11b..3494fbf0c6 100644 --- a/detections/endpoint/ssa___sdelete_application_execution.yml +++ b/detections/endpoint/ssa___sdelete_application_execution.yml @@ -45,6 +45,7 @@ references: tags: analytic_story: - Information Sabotage + cis20: [] confidence: 70 context: - Source:Endpoint @@ -60,6 +61,7 @@ tags: - T1485 - T1070.004 - T1070 + nist: [] observable: - name: dest_user_id type: User diff --git a/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml b/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml index da3a6dc607..502d796896 100644 --- a/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml @@ -53,6 +53,7 @@ tags: analytic_story: - Ingress Tool Transfer automated_detection_testing: passed + cis20: [] confidence: 100 context: - Source:Endpoint @@ -67,6 +68,7 @@ tags: destination. mitre_attack_id: - T1105 + nist: [] observable: - name: dest_user_id type: User