mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
removing CODEOWNERS
This commit is contained in:
@@ -1,2 +0,0 @@
|
||||
# Set a default so everything is owned by a codeowner
|
||||
* @okta-groups/sg-apps-strt-admin
|
||||
+1
-1
Submodule contentctl updated: bdc28c428f...cb6605ea65
+1
-1
@@ -5,7 +5,7 @@
|
||||
"id": {
|
||||
"group": null,
|
||||
"name": "DA-ESS-ContentUpdate",
|
||||
"version": "4.23.0"
|
||||
"version": "4.24.0"
|
||||
},
|
||||
"author": [
|
||||
{
|
||||
|
||||
+1723
-1491
File diff suppressed because it is too large
Load Diff
+3
-3
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-02-14T00:54:24 UTC
|
||||
# On Date: 2024-02-15T21:14:52 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -10,7 +10,7 @@
|
||||
is_configured = false
|
||||
state = enabled
|
||||
state_change_requires_restart = false
|
||||
build = 20240214005416
|
||||
build = 20240215211230
|
||||
|
||||
[triggers]
|
||||
reload.analytic_stories = simple
|
||||
@@ -26,7 +26,7 @@ reload.es_investigations = simple
|
||||
|
||||
[launcher]
|
||||
author = Splunk
|
||||
version = 4.23.0
|
||||
version = 4.24.0
|
||||
description = Explore the Analytic Stories included with ES Content Updates.
|
||||
|
||||
[ui]
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-02-14T00:54:24 UTC
|
||||
# On Date: 2024-02-15T21:14:52 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+2
-2
@@ -1,8 +1,8 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-02-14T00:54:24 UTC
|
||||
# On Date: 2024-02-15T21:14:52 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
[content-version]
|
||||
version = 4.23.0
|
||||
version = 4.24.0
|
||||
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-02-14T00:54:24 UTC
|
||||
# On Date: 2024-02-15T21:14:52 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+85
-5
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-02-14T00:54:24 UTC
|
||||
# On Date: 2024-02-15T21:14:52 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -633,6 +633,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_admin_consent_bypassed_by_service_principal_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_application_administrator_role_assigned_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -657,6 +661,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_fullaccessasapp_permission_assigned_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_global_administrator_role_assigned_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -689,6 +697,14 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_multiple_service_principals_created_by_sp_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_multiple_service_principals_created_by_user_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_multiple_users_failing_to_authenticate_from_ip_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -725,6 +741,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_privileged_graph_api_permission_assigned_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_privileged_role_assigned_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -733,6 +753,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_service_principal_authentication_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[azure_ad_service_principal_created_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1121,6 +1145,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_admin_consent_bypassed_by_service_principal_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_advanced_audit_disabled_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1161,6 +1189,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_fullaccessasapp_permission_assigned_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_high_number_of_failed_authentications_for_user_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1193,6 +1225,18 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_multiple_mailboxes_accessed_via_api_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_multiple_service_principals_created_by_sp_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_multiple_service_principals_created_by_user_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_multiple_users_failing_to_authenticate_from_ip_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1205,6 +1249,18 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_oauth_app_mailbox_access_via_ews_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_oauth_app_mailbox_access_via_graph_api_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_privileged_graph_api_permission_assigned_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[o365_pst_export_alert_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -1421,6 +1477,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[kubernetes_aws_detect_rbac_authorization_by_account_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[kubernetes_aws_detect_sensitive_role_access_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -3165,6 +3225,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[network_traffic_to_active_directory_web_services_protocol_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[nishang_powershelltcponeline_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -5225,6 +5289,18 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_privilege_escalation_suspicious_process_elevation_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_privilege_escalation_system_process_without_system_parent_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_privilege_escalation_user_process_spawn_system_process_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_process_commandline_discovery_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -5501,6 +5577,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_soaphound_binary_execution_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[windows_spearphishing_attachment_connect_to_none_ms_office_domain_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -6033,6 +6113,10 @@ description = Update this macro to limit the output results to filter out false
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[ivanti_connect_secure_ssrf_in_saml_component_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
|
||||
[ivanti_connect_secure_system_information_access_via_auth_bypass_filter]
|
||||
definition = search *
|
||||
description = Update this macro to limit the output results to filter out false positives.
|
||||
@@ -6431,10 +6515,6 @@ description = customer specific splunk configurations(eg- index, source, sourcet
|
||||
definition = (eventName = CreateNetworkAcl OR eventName = CreateNetworkAclEntry OR eventName = DeleteNetworkAcl OR eventName = DeleteNetworkAclEntry OR eventName = ReplaceNetworkAclEntry OR eventName = ReplaceNetworkAclAssociation)
|
||||
description = This is a list of AWS event names that are associated with Network ACLs
|
||||
|
||||
[notable]
|
||||
definition = index=notable
|
||||
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
|
||||
[o365_graph]
|
||||
definition = sourcetype=o365:graph:api
|
||||
description = customer specific splunk configurations(eg- index, source, sourcetype). Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
|
||||
+4248
-3328
File diff suppressed because it is too large
Load Diff
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-02-14T00:54:24 UTC
|
||||
# On Date: 2024-02-15T21:14:52 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security_content
|
||||
# On Date: 2024-02-14T00:54:24 UTC
|
||||
# On Date: 2024-02-15T21:14:52 UTC
|
||||
# Author: Splunk Threat Research Team - Splunk
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
@@ -1 +1 @@
|
||||
{"version": {"name": "v4.23.0", "published_at": "2024-01-30T21:17:01Z"}}
|
||||
{"version": {"name": "v4.24.0", "published_at": "2024-02-15T21:19:37Z"}}
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Anomalous usage of Archive Tools
|
||||
id: 63614a58-10e2-4c6c-ae81-ea1113681439
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following detection identifies the usage of archive tools from the
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Anomalous usage of Archive Tools has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Cobalt Strike", "NOBELIUM Group", "Insider Threat"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Attempt To Delete Services
|
||||
id: a0c8c292-d01a-11eb-aa18-acde48001122
|
||||
version: 5
|
||||
version: 6
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies Windows Service Control, `sc.exe`,
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Attempt To Delete Services has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig", "Ransomware"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Attempt To Disable Services
|
||||
id: afb31de4-d023-11eb-98d5-acde48001122
|
||||
version: 5
|
||||
version: 6
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies Windows Service Control, `sc.exe`,
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Attempt To Disable Services has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig", "Ransomware"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Attempted Credential Dump From Registry via Reg exe
|
||||
id: 14038953-e5f2-4daf-acff-5452062baf03
|
||||
version: 6
|
||||
version: 7
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the use of `reg.exe` attempting to
|
||||
@@ -23,7 +23,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Attempted Credential Dump From Registry via Reg exe has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Credential Dumping"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: BCDEdit Failure Recovery Modification
|
||||
id: 76d79d6e-25bb-40f6-b3b2-e0a6b7e5ea13
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This search looks for flags passed to bcdedit.exe modifications to the
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "BCDEdit Failure Recovery Modification has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Ryuk Ransomware", "Ransomware", "Information Sabotage"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Clear Unallocated Sector Using Cipher App
|
||||
id: 8f907d90-6173-11ec-9c23-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: this search is to detect execution of `cipher.exe` to clear the unallocated
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Clear Unallocated Sector Using Cipher App has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Ransomware", "Information Sabotage"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Create Local Admin Accounts Using Net Exe
|
||||
id: 2dbdfc95-9c0f-433e-95f1-a376f1ae8bf7
|
||||
version: 2
|
||||
version: 3
|
||||
status: validation
|
||||
detection_type: STREAMING
|
||||
description: The following analytic detects the creation of local administrator accounts
|
||||
@@ -37,7 +37,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Create Local Admin Accounts Using Net Exe has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig", "Ransomware"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Create Local User Accounts Using Net Exe
|
||||
id: 1ee0fff0-9642-421b-8e13-9aa6fba4ace3
|
||||
version: 5
|
||||
version: 6
|
||||
status: validation
|
||||
detection_type: STREAMING
|
||||
description: The following analytic detects the creation of local administrator accounts
|
||||
@@ -33,7 +33,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Create Local User Accounts Using Net Exe has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig", "Ransomware"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Delete A Net User
|
||||
id: 8776d79c-d26e-11eb-9a56-acde48001122
|
||||
version: 7
|
||||
version: 8
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This analytic will detect a suspicious net.exe/net1.exe command-line
|
||||
@@ -23,7 +23,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Delete A Net User has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig", "Ransomware"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Deleting Shadow Copies
|
||||
id: fd40c537-53d0-4c28-9b7e-77cfd28a49c8
|
||||
version: 4
|
||||
version: 5
|
||||
status: validation
|
||||
detection_type: STREAMING
|
||||
description: The vssadmin.exe utility is used to interact with the Volume Shadow Copy
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Deleting Shadow Copies has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Clop Ransomware", "Ransomware"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Deny Permission using Cacls Utility
|
||||
id: b76eae28-cd25-11eb-9c92-acde48001122
|
||||
version: 6
|
||||
version: 7
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the use of `cacls.exe`, `icacls.exe`
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Deny Permission using Cacls Utility has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig", "Information Sabotage"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect PowerShell Applications Spawning cmd exe
|
||||
id: d20a18cb-fd70-4ffa-a844-25126e0b0d94
|
||||
version: 2
|
||||
version: 3
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies parent processes that are powershell,
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Detect PowerShell Applications Spawning cmd exe has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious Command-Line Executions", "Insider Threat"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Prohibited Browsers Spawning cmd exe
|
||||
id: c10a18cb-fa70-4dfa-a944-25026e1b0c94
|
||||
version: 7
|
||||
version: 8
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies parent processes that are browsers,
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Detect Prohibited Browsers Spawning cmd exe has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious Command-Line Executions", "Insider Threat"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Detect Prohibited Office Applications Spawning cmd exe
|
||||
id: c10a18cb-fd70-44fb-a8f4-25026a0b0c94
|
||||
version: 2
|
||||
version: 3
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies parent processes that are office/productivity
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Detect Prohibited Office Applications Spawning cmd exe has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious Command-Line Executions", "Insider Threat"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Detect RClone Command-Line Usage
|
||||
id: e8b74268-5454-11ec-a799-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This analytic identifies commonly used command-line arguments used by
|
||||
@@ -28,7 +28,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Detect RClone Command-Line Usage has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["DarkSide Ransomware", "Ransomware", "Insider Threat"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Disable Net User Account
|
||||
id: ba858b08-d26c-11eb-af9b-acde48001122
|
||||
version: 6
|
||||
version: 7
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This analytic will identify a suspicious command-line that disables a
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Disable Net User Account has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig", "Ransomware"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: DNS Exfiltration Using Nslookup App
|
||||
id: 2452e632-9e0d-11eb-34ba-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This search is to detect potential DNS exfiltration using nslookup application.
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "DNS Exfiltration Using Nslookup App has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious DNS Traffic", "Dynamic DNS", "Data Exfiltration", "Command And Control"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Fsutil Zeroing File
|
||||
id: f792cdc9-43ee-4429-a3c0-ffce4fed1a85
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This search is to detect a suspicious fsutil process to zeroing a target
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Fsutil Zeroing File has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Ransomware", "Insider Threat", "Information Sabotage"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Grant Permission Using Cacls Utility
|
||||
id: c6da561a-cd29-11eb-ae65-acde48001122
|
||||
version: 6
|
||||
version: 7
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the use of `cacls.exe`, `icacls.exe`
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Grant Permission Using Cacls Utility has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig", "Insider Threat"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Hiding Files And Directories With Attrib exe
|
||||
id: 028e4406-6176-11ec-aec2-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: Attackers leverage an existing Windows binary, attrib.exe, to mark specific
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Hiding Files And Directories With Attrib exe has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Windows Defense Evasion Tactics", "Windows Persistence Techniques", "Information Sabotage", "Insider Threat"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Modify ACLs Permission Of Files Or Folders
|
||||
id: 9ae9a48a-cdbe-11eb-875a-acde48001122
|
||||
version: 6
|
||||
version: 7
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This analytic identifies suspicious modification of ACL permission to
|
||||
@@ -23,7 +23,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Modify ACLs Permission Of Files Or Folders has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["XMRig"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Office Product Spawning Windows Script Host
|
||||
id: 3ea3851a-8736-41a0-bc09-7e4485b48fa6
|
||||
version: 4
|
||||
version: 5
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic will identify a Windows Office Product spawning
|
||||
@@ -22,7 +22,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Office Product Spawning Windows Script Host has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Spearphishing Attachments"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Resize Shadowstorage Volume
|
||||
id: dbc30554-d27e-11eb-9e5e-acde48001122
|
||||
version: 5
|
||||
version: 6
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the resizing of shadowstorage using
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Resize Shadowstorage Volume has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Clop Ransomware", "Ransomware"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Sdelete Application Execution
|
||||
id: fcc52b9a-4616-11ec-8454-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This analytic will detect the execution of sdelete.exe attempting to
|
||||
@@ -32,7 +32,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Sdelete Application Execution has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Information Sabotage", "Insider Threat"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Services lolbas Execution Process Spawn
|
||||
id: 0d85fde3-0de9-4eec-b386-6a8ba70f3935
|
||||
version: 4
|
||||
version: 5
|
||||
status: validation
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies services.exe spawning a LOLBAS execution
|
||||
@@ -33,7 +33,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Services lolbas Execution Process Spawn has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious Command-Line Executions", "Insider Threat"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: System Process Running from Unexpected Location
|
||||
id: 28179107-099a-464a-94d3-08301e6c055f
|
||||
version: 7
|
||||
version: 8
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: An attacker tries might try to use different version of a system command
|
||||
@@ -132,7 +132,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "System Process Running from Unexpected Location has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Windows Defense Evasion Tactics", "Masquerading - Rename System Utilities"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: WBAdmin Delete System Backups
|
||||
id: 71efbf52-4dbb-4c00-a520-306aa546cbb7
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This search looks for flags passed to wbadmin.exe (Windows Backup Administrator
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "WBAdmin Delete System Backups has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Ryuk Ransomware", "Ransomware"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: WevtUtil Usage To Clear Logs
|
||||
id: 5438113c-cdd9-11eb-93b8-acde48001122
|
||||
version: 4
|
||||
version: 5
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The wevtutil.exe application is the windows event log utility. This searches
|
||||
@@ -22,7 +22,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "WevtUtil Usage To Clear Logs has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Windows Log Manipulation", "Ransomware", "Clop Ransomware", "Insider Threat", "CISA AA22-264A"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Wevtutil Usage To Disable Logs
|
||||
id: a4bdc944-cdd9-11eb-ac97-acde48001122
|
||||
version: 4
|
||||
version: 5
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This search is to detect execution of wevtutil.exe to disable logs. This
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Wevtutil Usage To Disable Logs has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Windows Log Manipulation", "Ransomware", "Insider Threat", "Information Sabotage"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Bits Job Persistence
|
||||
id: 1e25e97a-8ea4-11ec-9767-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following query identifies Microsoft Background Intelligent Transfer
|
||||
@@ -26,7 +26,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Bits Job Persistence has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["BITS Jobs", "Living Off The Land"],
|
||||
|
||||
+4
-4
@@ -1,6 +1,6 @@
|
||||
name: Windows Bitsadmin Download File
|
||||
id: d76e8188-8f5a-11ec-ace4-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following query identifies Microsoft Background Intelligent Transfer
|
||||
@@ -28,7 +28,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Bitsadmin Download File has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Ingress Tool Transfer", "BITS Jobs", "DarkSide Ransomware", "Living Off The Land"],
|
||||
@@ -38,7 +38,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
duration = 0,
|
||||
impact = 70,
|
||||
impact_id = 4,
|
||||
kill_chain = [{"phase": "Exploitation", "phase_id": 4}, {"phase": "Installation", "phase_id": 5}, {"phase": "Command And Control", "phase_id": 6}],
|
||||
kill_chain = [{"phase": "Exploitation", "phase_id": 4}, {"phase": "Installation", "phase_id": 5}, {"phase": "Command and Control", "phase_id": 6}],
|
||||
nist = ["DE.AE"],
|
||||
risk_level = "Medium",
|
||||
category_uid = 2,
|
||||
@@ -111,7 +111,7 @@ tags:
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
- Installation
|
||||
- Command And Control
|
||||
- Command and Control
|
||||
mitre_attack_id:
|
||||
- T1197
|
||||
- T1105
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows CertUtil Decode File
|
||||
id: b06983f4-8f72-11ec-ab50-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: CertUtil.exe may be used to `encode` and `decode` a file, including PE
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows CertUtil Decode File has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Deobfuscate-Decode Files or Information", "Living Off The Land", "Forest Blizzard"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows CertUtil URLCache Download
|
||||
id: 8cb1ad38-8f6d-11ec-87a3-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: Certutil.exe may download a file from a remote destination using `-urlcache`.
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows CertUtil URLCache Download has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Ingress Tool Transfer", "DarkSide Ransomware", "Living Off The Land", "Forest Blizzard"],
|
||||
@@ -34,7 +34,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
duration = 0,
|
||||
impact = 90,
|
||||
impact_id = 5,
|
||||
kill_chain = [{"phase": "Command And Control", "phase_id": 6}],
|
||||
kill_chain = [{"phase": "Command and Control", "phase_id": 6}],
|
||||
nist = ["DE.AE"],
|
||||
risk_level = "Critical",
|
||||
category_uid = 2,
|
||||
@@ -102,7 +102,7 @@ tags:
|
||||
cis20:
|
||||
- CIS 10
|
||||
kill_chain_phases:
|
||||
- Command And Control
|
||||
- Command and Control
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
nist:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows CertUtil VerifyCtl Download
|
||||
id: 9ac29c40-8f6b-11ec-b19a-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: 'Certutil.exe may download a file from a remote destination using `-VerifyCtl`.
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows CertUtil VerifyCtl Download has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Ingress Tool Transfer", "DarkSide Ransomware", "Living Off The Land"],
|
||||
@@ -34,7 +34,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
duration = 0,
|
||||
impact = 90,
|
||||
impact_id = 5,
|
||||
kill_chain = [{"phase": "Command And Control", "phase_id": 6}],
|
||||
kill_chain = [{"phase": "Command and Control", "phase_id": 6}],
|
||||
nist = ["DE.AE"],
|
||||
risk_level = "Critical",
|
||||
category_uid = 2,
|
||||
@@ -102,7 +102,7 @@ tags:
|
||||
cis20:
|
||||
- CIS 10
|
||||
kill_chain_phases:
|
||||
- Command And Control
|
||||
- Command and Control
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
nist:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows COM Hijacking InprocServer32 Modification
|
||||
id: 0ae05a0f-bc84-456b-822a-a5b9c081c7ca
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the use of reg.exe performing an add
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows COM Hijacking InprocServer32 Modification has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Living Off The Land"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Curl Upload to Remote Destination
|
||||
id: cc8d046a-543b-11ec-b864-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: 'The following analytic identifies the use of Windows Curl.exe uploading
|
||||
@@ -36,7 +36,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Curl Upload to Remote Destination has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Ingress Tool Transfer", "Insider Threat"],
|
||||
@@ -46,7 +46,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
duration = 0,
|
||||
impact = 80,
|
||||
impact_id = 5,
|
||||
kill_chain = [{"phase": "Command And Control", "phase_id": 6}],
|
||||
kill_chain = [{"phase": "Command and Control", "phase_id": 6}],
|
||||
nist = ["DE.AE"],
|
||||
risk_level = "Critical",
|
||||
category_uid = 2,
|
||||
@@ -112,7 +112,7 @@ tags:
|
||||
cis20:
|
||||
- CIS 10
|
||||
kill_chain_phases:
|
||||
- Command And Control
|
||||
- Command and Control
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
nist:
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Default Group Policy Object Modified with GPME
|
||||
id: bcb55c13-067b-4648-98f3-627010f72520
|
||||
version: 3
|
||||
version: 5
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the potential edition of a default
|
||||
@@ -27,7 +27,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Default Group Policy Object Modified with GPME has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Active Directory Privilege Escalation"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Defender Tools in Non Standard Path
|
||||
id: c205bd2e-cd5b-4224-8510-578a2a1f83d7
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies usage of the MPCmdRun utility that
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Defender Tools in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Living Off The Land"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Diskshadow Proxy Execution
|
||||
id: aa502688-9037-11ec-842d-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: DiskShadow.exe is a Microsoft Signed binary present on Windows Server.
|
||||
@@ -22,7 +22,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Diskshadow Proxy Execution has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Living Off The Land"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows DotNet Binary in Non Standard Path
|
||||
id: 21179107-099a-324a-94d3-08301e6c065f
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies native .net binaries within the Windows
|
||||
@@ -52,7 +52,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows DotNet Binary in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Masquerading - Rename System Utilities", "Unusual Processes", "Ransomware", "Signed Binary Proxy Execution InstallUtil", "WhisperGate"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Exchange PowerShell Module Usage
|
||||
id: 1118bc65-b0c7-4589-bc2f-ad6802fd0909
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: 'The following analytic identifies the usage of Exchange PowerShell modules
|
||||
@@ -36,7 +36,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"device.hostname": device_hostname, "process.file.path": process_file_path, "process.uid": process_uid, "process.cmd_line": process_cmd_line, "actor.user.uid": actor_user_uid, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Exchange PowerShell Module Usage has been triggered on " + device_hostname + " by " + "Unknown" + ".",
|
||||
users = [{"name": "Unknown", "uid": actor_user.uid}],
|
||||
users = [{"name": "Unknown", "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["ProxyShell", "CISA AA22-264A"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Execute Arbitrary Commands with MSDT
|
||||
id: f253f9c2-10f0-4cc8-b469-f505ba8c2038
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies a recently disclosed arbitraty command
|
||||
@@ -25,7 +25,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Execute Arbitrary Commands with MSDT has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Microsoft Support Diagnostic Tool Vulnerability CVE-2022-30190"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows File Share Discovery With Powerview
|
||||
id: ec4f671e-c736-4f78-a4c0-8fe809e952e5
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the use of the Invoke-ShareFinder PowerShell
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"device.hostname": device_hostname, "process.file.path": process_file_path, "process.uid": process_uid, "process.cmd_line": process_cmd_line, "actor.user.uid": actor_user_uid, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows File Share Discovery With Powerview has been triggered on " + device_hostname + " by " + "Unknown" + ".",
|
||||
users = [{"name": "Unknown", "uid": actor_user.uid}],
|
||||
users = [{"name": "Unknown", "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Active Directory Privilege Escalation"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Findstr GPP Discovery
|
||||
id: 73ed0f19-080e-4917-b7c6-56e1760a50d4
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the use of the findstr command employed
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Findstr GPP Discovery has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Active Directory Privilege Escalation"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Ingress Tool Transfer Using Explorer
|
||||
id: 695bfad6-9662-4f9e-a576-bf02a951aa60
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the Windows Explorer process with a
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Ingress Tool Transfer Using Explorer has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["DarkCrystal RAT"],
|
||||
@@ -34,7 +34,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
duration = 0,
|
||||
impact = 50,
|
||||
impact_id = 3,
|
||||
kill_chain = [{"phase": "Command And Control", "phase_id": 6}],
|
||||
kill_chain = [{"phase": "Command and Control", "phase_id": 6}],
|
||||
nist = ["DE.AE"],
|
||||
risk_level = "Low",
|
||||
category_uid = 2,
|
||||
@@ -97,7 +97,7 @@ tags:
|
||||
cis20:
|
||||
- CIS 10
|
||||
kill_chain_phases:
|
||||
- Command And Control
|
||||
- Command and Control
|
||||
mitre_attack_id:
|
||||
- T1105
|
||||
nist:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows LOLBin Binary in Non Standard Path
|
||||
id: 25689101-012a-324a-94d3-08301e6c065a
|
||||
version: 7
|
||||
version: 8
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies native living off the land binaries
|
||||
@@ -39,7 +39,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows LOLBin Binary in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Ransomware", "WhisperGate"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows MSHTA Child Process
|
||||
id: f63f7e9c-9526-11ec-9fc7-acde48001122
|
||||
version: 5
|
||||
version: 6
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies child processes spawning from "mshta.exe".
|
||||
@@ -22,7 +22,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows MSHTA Child Process has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious MSHTA Activity", "Living Off The Land"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows MSHTA Command-Line URL
|
||||
id: 9b35c538-94ef-11ec-9439-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This analytic identifies when Microsoft HTML Application Host (mshta.exe)
|
||||
@@ -23,7 +23,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows MSHTA Command-Line URL has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious MSHTA Activity", "Living Off The Land"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows MSHTA Inline HTA Execution
|
||||
id: 24962154-9524-11ec-9333-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies "mshta.exe" execution with inline protocol
|
||||
@@ -22,7 +22,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows MSHTA Inline HTA Execution has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious MSHTA Activity", "Living Off The Land"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Odbcconf Load Response File
|
||||
id: 7b6c3fac-0c37-4efc-a85e-de88f42b6763
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the odbcconf.exe, Windows Open Database
|
||||
@@ -22,7 +22,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Odbcconf Load Response File has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Living Off The Land"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows OS Credential Dumping with Ntdsutil Export NTDS
|
||||
id: dad9ddec-a72a-47be-87b6-a0f7ba98ed6e
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: 'Monitor for signs that Ntdsutil is being used to Extract Active Directory
|
||||
@@ -27,7 +27,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows OS Credential Dumping with Ntdsutil Export NTDS has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Credential Dumping", "HAFNIUM Group", "Living Off The Land", "Volt Typhoon"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows OS Credential Dumping with Procdump
|
||||
id: e102e297-dbe6-4a19-b319-5c08f4c19a06
|
||||
version: 4
|
||||
version: 5
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: 'Detect procdump.exe dumping the lsass process. This query looks for
|
||||
@@ -27,7 +27,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows OS Credential Dumping with Procdump has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Credential Dumping", "HAFNIUM Group"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Powershell Connect to Internet With Hidden Window
|
||||
id: 477e068e-8b6d-11ec-b6c1-81af21670352
|
||||
version: 5
|
||||
version: 6
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following hunting analytic identifies PowerShell commands utilizing
|
||||
@@ -26,7 +26,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Powershell Connect to Internet With Hidden Window has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Malicious PowerShell", "Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns", "HAFNIUM Group", "Log4Shell CVE-2021-44228"],
|
||||
|
||||
Vendored
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows PowerShell Disabled Kerberos Pre-Authentication Discovery Get-ADUser
|
||||
id: d57b4d91-fc91-4482-a325-47693cced1eb
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104)
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"device.hostname": device_hostname, "process.file.path": process_file_path, "process.uid": process_uid, "process.cmd_line": process_cmd_line, "actor.user.uid": actor_user_uid, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows PowerShell Disabled Kerberos Pre-Authentication Discovery Get-ADUser has been triggered on " + device_hostname + " by " + "Unknown" + ".",
|
||||
users = [{"name": "Unknown", "uid": actor_user.uid}],
|
||||
users = [{"name": "Unknown", "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Active Directory Kerberos Attacks"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows PowerShell Disabled Kerberos Pre-Authentication Discovery With PowerView
|
||||
id: dc3f2af7-ca69-47ce-a122-9f9787e19417
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic utilizes PowerShell Script Block Logging (EventCode=4104)
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"device.hostname": device_hostname, "process.file.path": process_file_path, "process.uid": process_uid, "process.cmd_line": process_cmd_line, "actor.user.uid": actor_user_uid, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows PowerShell Disabled Kerberos Pre-Authentication Discovery With PowerView has been triggered on " + device_hostname + " by " + "Unknown" + ".",
|
||||
users = [{"name": "Unknown", "uid": actor_user.uid}],
|
||||
users = [{"name": "Unknown", "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Active Directory Kerberos Attacks"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Powershell DownloadFile
|
||||
id: 46440222-81d5-44b1-a376-19dcd70d1b08
|
||||
version: 4
|
||||
version: 5
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the use of PowerShell downloading a
|
||||
@@ -22,7 +22,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Powershell DownloadFile has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Malicious PowerShell", "Ingress Tool Transfer", "Log4Shell CVE-2021-44228"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows PowerShell Start-BitsTransfer
|
||||
id: 0bafd086-8f61-11ec-996e-acde48001122
|
||||
version: 4
|
||||
version: 5
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: Start-BitsTransfer is the PowerShell "version" of BitsAdmin.exe. Similar
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows PowerShell Start-BitsTransfer has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["BITS Jobs", "Living Off The Land"],
|
||||
@@ -34,7 +34,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
duration = 0,
|
||||
impact = 70,
|
||||
impact_id = 4,
|
||||
kill_chain = [{"phase": "Exploitation", "phase_id": 4}, {"phase": "Installation", "phase_id": 5}, {"phase": "Command And Control", "phase_id": 6}],
|
||||
kill_chain = [{"phase": "Exploitation", "phase_id": 4}, {"phase": "Installation", "phase_id": 5}, {"phase": "Command and Control", "phase_id": 6}],
|
||||
nist = ["DE.AE"],
|
||||
risk_level = "Medium",
|
||||
category_uid = 2,
|
||||
@@ -102,7 +102,7 @@ tags:
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
- Installation
|
||||
- Command And Control
|
||||
- Command and Control
|
||||
mitre_attack_id:
|
||||
- T1197
|
||||
- T1105
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows PowerSploit GPP Discovery
|
||||
id: fdef746e-71fb-41ce-8ab2-b4a5a6b50ca2
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the use of the Get-GPPPassword PowerShell
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"device.hostname": device_hostname, "process.file.path": process_file_path, "process.uid": process_uid, "process.cmd_line": process_cmd_line, "actor.user.uid": actor_user_uid, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows PowerSploit GPP Discovery has been triggered on " + device_hostname + " by " + "Unknown" + ".",
|
||||
users = [{"name": "Unknown", "uid": actor_user.uid}],
|
||||
users = [{"name": "Unknown", "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Active Directory Privilege Escalation"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rasautou DLL Execution
|
||||
id: 6f42b8ce-1e15-11ec-ad5a-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the Windows Windows Remote Auto Dialer,
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rasautou DLL Execution has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Windows Defense Evasion Tactics", "Living Off The Land"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard Path
|
||||
id: c842931e-661f-42bc-a4df-0460d93cfb69
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies AccCheckConsole.exe which is a native
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities Acccheckconsole exe LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
Vendored
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path
|
||||
id: ecaaf956-c516-4980-b08e-8c01c19614ca
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies adplus.exe which is a native living
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities Adplus exe LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
Vendored
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path
|
||||
id: 3284e4f4-67f7-49b6-ad5e-a8fcead2eef8
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies Advpack.dll which is a native living
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities Advpack dll LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
dist/ssa/srs/ssa___windows_rename_system_utilities_agentexecutor_exe_lolbas_in_non_standard_path.yml
Vendored
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path
|
||||
id: e124f71f-11bc-47e4-9931-6046d256005d
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies AgentExecutor.exe which is a native
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities Agentexecutor exe LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
Vendored
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path
|
||||
id: 057c06c7-ef31-4749-b5c9-199152e53a06
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies AppInstaller.exe which is a native
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities Appinstaller exe LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
Vendored
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path
|
||||
id: 93862a89-abe0-4094-909a-08ec390aa5e3
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies Appvlp.exe which is a native living
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities Appvlp exe LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities Aspnet compiler exe LOLBAS in Non Standard Path
|
||||
id: d75cc561-3828-4d0a-92c4-0eb93bfe0929
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies Aspnet_Compiler.exe which is a native
|
||||
@@ -21,7 +21,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities Aspnet compiler exe LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities At exe LOLBAS in Non Standard Path
|
||||
id: 6401d583-0052-4dc5-a713-68b510826d2b
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies At.exe which is a native living off
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities At exe LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
Vendored
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path
|
||||
id: b8da7ea5-8c16-4eff-9787-54ec271159e0
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies Atbroker.exe which is a native living
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rename System Utilities Atbroker exe LOLBAS in Non Standard Path has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Unusual Processes", "Living Off The Land"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Rundll32 Comsvcs Memory Dump
|
||||
id: 76bb9e35-f314-4c3d-a385-83c72a13ce4e
|
||||
version: 7
|
||||
version: 8
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies memory dumping using comsvcs.dll with
|
||||
@@ -20,7 +20,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rundll32 Comsvcs Memory Dump has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Credential Dumping", "Suspicious Rundll32 Activity"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Rundll32 Inline HTA Execution
|
||||
id: 0caa1dd6-94f5-11ec-9786-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies "rundll32.exe" execution with inline
|
||||
@@ -24,7 +24,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Rundll32 Inline HTA Execution has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious MSHTA Activity", "NOBELIUM Group", "Living Off The Land"],
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Script Host Spawn MSBuild
|
||||
id: 92886f1c-9b11-11ec-848a-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: This analytic is to detect a suspicious child process of MSBuild spawned
|
||||
@@ -23,7 +23,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows Script Host Spawn MSBuild has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Trusted Developer Utilities Proxy Execution MSBuild", "Living Off The Land"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows System Binary Proxy Execution Compiled HTML File Decompile
|
||||
id: 11c32b19-05a6-48a8-ab28-18dbd9ec5d50
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the decompile parameter with the HTML
|
||||
@@ -22,7 +22,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows System Binary Proxy Execution Compiled HTML File Decompile has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious Compiled HTML Activity", "Living Off The Land"],
|
||||
|
||||
Vendored
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows System Binary Proxy Execution Compiled HTML File URL In Command Line
|
||||
id: 0fec631a-7c9b-4e4c-b28b-93260953e25f
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies hh.exe (HTML Help) execution of a Compiled
|
||||
@@ -27,7 +27,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows System Binary Proxy Execution Compiled HTML File URL In Command Line has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious Compiled HTML Activity", "Living Off The Land"],
|
||||
|
||||
+2
-2
@@ -1,7 +1,7 @@
|
||||
name: Windows System Binary Proxy Execution Compiled HTML File Using InfoTech Storage
|
||||
Handlers
|
||||
id: ba0c2450-caea-4086-ac3a-a71e2659754b
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies hh.exe (HTML Help) execution of a Compiled
|
||||
@@ -30,7 +30,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows System Binary Proxy Execution Compiled HTML File Using InfoTech Storage Handlers has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Suspicious Compiled HTML Activity", "Living Off The Land"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows System Binary Proxy Execution MSIExec DLLRegisterServer
|
||||
id: 8d1d5570-722c-49a3-996c-2e2cceef5163
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the usage of msiexec.exe using the
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows System Binary Proxy Execution MSIExec DLLRegisterServer has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Windows System Binary Proxy Execution MSIExec"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows System Binary Proxy Execution MSIExec Remote Download
|
||||
id: 92cbbf0f-9a6b-4e9d-8c35-cc9244a4e3d5
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies msiexec.exe with http in the command-line.
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows System Binary Proxy Execution MSIExec Remote Download has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Windows System Binary Proxy Execution MSIExec"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows System Binary Proxy Execution MSIExec Unregister DLL
|
||||
id: df76a8d1-92e1-4ec9-b8f7-695b5838703e
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies the usage of msiexec.exe using the
|
||||
@@ -19,7 +19,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows System Binary Proxy Execution MSIExec Unregister DLL has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Windows System Binary Proxy Execution MSIExec"],
|
||||
|
||||
+2
-2
@@ -1,6 +1,6 @@
|
||||
name: Windows WMIPrvse Spawn MSBuild
|
||||
id: 76b3b290-9b31-11ec-a934-acde48001122
|
||||
version: 3
|
||||
version: 4
|
||||
status: production
|
||||
detection_type: STREAMING
|
||||
description: The following analytic identifies wmiprvse.exe spawning msbuild.exe.
|
||||
@@ -23,7 +23,7 @@ search: ' $main = from source | eval timestamp = time | eval metadata_uid = me
|
||||
time = timestamp,
|
||||
evidence = {"process.pid": process_pid, "process.file.path": process_file_path, "process.file.name": process_file_name, "process.cmd_line": process_cmd_line, "actor.user.name": actor_user_name, "actor.process.pid": actor_process_pid, "actor.process.file.path": actor_process_file_path, "actor.process.file.name": actor_process_file_name, "device.hostname": device_hostname, "sourceType": metadata.source_type, "source": metadata.source},
|
||||
message = "Windows WMIPrvse Spawn MSBuild has been triggered on " + device_hostname + " by " + actor_user_name + ".",
|
||||
users = [{"name": actor_user_name, "uid": actor_user.uid}],
|
||||
users = [{"name": actor_user_name, "uuid": actor_user.uuid, "uid": actor_user.uid}],
|
||||
activity_id = 1,
|
||||
cis_csc = [{"control": "CIS 10", "version": 8}],
|
||||
analytic_stories = ["Trusted Developer Utilities Proxy Execution MSBuild", "Living Off The Land"],
|
||||
|
||||
Reference in New Issue
Block a user