mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
name: Email Attachments With Lots Of Spaces
|
||||
id: 56e877a6-1455-4479-ada6-0550dc1e22f8
|
||||
version: 2
|
||||
date: '2017-09-19'
|
||||
date: '2023-04-14'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -32,8 +32,9 @@ known_false_positives: None at this time
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
- 'Emotet Malware DHS Report TA18-201A '
|
||||
- Hermetic Wiper
|
||||
- Suspicious Emails
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious Email Attachment Extensions
|
||||
id: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084
|
||||
version: 3
|
||||
date: '2020-07-22'
|
||||
date: '2023-04-14'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -29,8 +29,9 @@ known_false_positives: None identified
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
- 'Emotet Malware DHS Report TA18-201A '
|
||||
- Hermetic Wiper
|
||||
- Suspicious Emails
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Active Setup Registry Autostart
|
||||
id: f64579c0-203f-11ec-abcc-acde48001122
|
||||
version: 3
|
||||
date: '2022-11-14'
|
||||
date: '2023-04-14'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,9 +36,10 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1547/014/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Data Destruction
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
- Windows Persistence Techniques
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Add or Set Windows Defender Exclusion
|
||||
id: 773b66fe-4dd9-11ec-8289-acde48001122
|
||||
version: 1
|
||||
date: '2021-11-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,11 +32,12 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Remcos
|
||||
- Windows Defense Evasion Tactics
|
||||
- WhisperGate
|
||||
- CISA AA22-320A
|
||||
- AgentTesla
|
||||
- Remcos
|
||||
- Windows Defense Evasion Tactics
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AdsiSearcher Account Discovery
|
||||
id: de7fcadc-04f3-11ec-a241-acde48001122
|
||||
version: 2
|
||||
date: '2022-11-13'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -25,8 +25,9 @@ references:
|
||||
- https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
- Active Directory Discovery
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Any Powershell DownloadFile
|
||||
id: 1a93b7ea-7af7-11eb-adb5-acde48001122
|
||||
version: 3
|
||||
date: '2022-04-07'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,11 +32,12 @@ references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- DarkCrystal RAT
|
||||
- Ingress Tool Transfer
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Ingress Tool Transfer
|
||||
- Data Destruction
|
||||
- Log4Shell CVE-2021-44228
|
||||
- DarkCrystal RAT
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Attempt To Stop Security Service
|
||||
id: c8e349c6-b97c-486e-8949-bd7bcd1f3910
|
||||
version: 4
|
||||
date: '2020-07-21'
|
||||
date: '2023-04-14'
|
||||
author: Rico Valdez, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,10 +29,11 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Disabling Security Tools
|
||||
- Trickbot
|
||||
- WhisperGate
|
||||
- Azorult
|
||||
- Trickbot
|
||||
- Disabling Security Tools
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 40
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Attempted Credential Dump From Registry via Reg exe
|
||||
id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
|
||||
version: 7
|
||||
date: '2022-11-15'
|
||||
date: '2023-04-14'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -28,10 +28,11 @@ references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Windows Registry Abuse
|
||||
- Credential Dumping
|
||||
- DarkSide Ransomware
|
||||
- Windows Registry Abuse
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Change Default File Association
|
||||
id: 462d17d8-1f71-11ec-ad07-acde48001122
|
||||
version: 1
|
||||
date: '2021-09-27'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,11 +29,12 @@ references:
|
||||
- https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Windows Registry Abuse
|
||||
- Prestige Ransomware
|
||||
- Windows Privilege Escalation
|
||||
- Windows Persistence Techniques
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Child Processes of Spoolsv exe
|
||||
id: aa0c4aeb-5b18-41c4-8c07-f1442d7599df
|
||||
version: 3
|
||||
date: '2020-03-16'
|
||||
date: '2023-04-14'
|
||||
author: Rico Valdez, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -28,8 +28,9 @@ known_false_positives: Some legitimate printer-related processes may show up as
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect Empire with PowerShell Script Block Logging
|
||||
id: bc1dc6b8-c954-11eb-bade-acde48001122
|
||||
version: 2
|
||||
date: '2022-02-24'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -40,8 +40,9 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Dump LSASS via comsvcs DLL
|
||||
id: 8943b567-f14d-4ee8-a0bb-2121d4ce3184
|
||||
version: 2
|
||||
date: '2020-02-21'
|
||||
date: '2023-04-14'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -24,14 +24,15 @@ references:
|
||||
- https://twitter.com/SBousseaden/status/1167417096374050817
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- Suspicious Rundll32 Activity
|
||||
- HAFNIUM Group
|
||||
- Living Off The Land
|
||||
- Industroyer2
|
||||
- CISA AA22-257A
|
||||
- HAFNIUM Group
|
||||
- CISA AA22-264A
|
||||
- Prestige Ransomware
|
||||
- Credential Dumping
|
||||
- CISA AA22-257A
|
||||
- Living Off The Land
|
||||
- Suspicious Rundll32 Activity
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: ETW Registry Disabled
|
||||
id: 8ed523ac-276b-11ec-ac39-acde48001122
|
||||
version: 3
|
||||
date: '2022-11-14'
|
||||
date: '2023-04-14'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,10 +31,11 @@ references:
|
||||
- https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
- Windows Persistence Techniques
|
||||
- Windows Registry Abuse
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Excessive File Deletion In WinDefender Folder
|
||||
id: b5baa09a-7a05-11ec-8da4-acde48001122
|
||||
version: 1
|
||||
date: '2022-01-20'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -27,6 +27,7 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Executable File Written in Administrative SMB Share
|
||||
id: f63c34fe-a435-11eb-935a-acde48001122
|
||||
version: 2
|
||||
date: '2021-11-18'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,12 +32,12 @@ references:
|
||||
- https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Active Directory Lateral Movement
|
||||
- Trickbot
|
||||
- Hermetic Wiper
|
||||
- Industroyer2
|
||||
- Active Directory Lateral Movement
|
||||
- Hermetic Wiper
|
||||
- Trickbot
|
||||
- Prestige Ransomware
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Executables Or Script Creation In Suspicious Path
|
||||
id: a7e3f0f0-ae42-11eb-b245-acde48001122
|
||||
version: 1
|
||||
date: '2021-10-06'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -37,24 +37,24 @@ references:
|
||||
- https://twitter.com/pr0xylife/status/1590394227758104576
|
||||
tags:
|
||||
analytic_story:
|
||||
- Double Zero Destructor
|
||||
- Data Destruction
|
||||
- XMRig
|
||||
- Remcos
|
||||
- WhisperGate
|
||||
- Hermetic Wiper
|
||||
- Industroyer2
|
||||
- Azorult
|
||||
- DarkCrystal RAT
|
||||
- AsyncRAT
|
||||
- Azorult
|
||||
- Brute Ratel C4
|
||||
- Double Zero Destructor
|
||||
- Industroyer2
|
||||
- AgentTesla
|
||||
- Qakbot
|
||||
- IcedID
|
||||
- Remcos
|
||||
- XMRig
|
||||
- Hermetic Wiper
|
||||
- Trickbot
|
||||
- Chaos Ransomware
|
||||
- LockBit Ransomware
|
||||
- AsyncRAT
|
||||
- Swift Slicer
|
||||
- LockBit Ransomware
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 40
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Impacket Lateral Movement Commandline Parameters
|
||||
id: 8ce07472-496f-11ec-ab3b-3e22fbd008af
|
||||
version: 3
|
||||
date: '2023-02-24'
|
||||
date: '2023-04-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -15,11 +15,12 @@ description: This analytic looks for the presence of suspicious commandline para
|
||||
tools for lateral movement and remote code execution.
|
||||
data_source:
|
||||
- Sysmon Event ID 1
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe (Processes.process = "*/Q /c * \\\\127.0.0.1\\*$*" AND Processes.process IN ("*2>&1*","*2>&1*")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `impacket_lateral_movement_commandline_parameters_filter`'
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe
|
||||
(Processes.process = "*/Q /c * \\\\127.0.0.1\\*$*" AND Processes.process IN ("*2>&1*","*2>&1*"))
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `impacket_lateral_movement_commandline_parameters_filter`'
|
||||
how_to_implement: To successfully implement this search, you need to be ingesting
|
||||
logs with the process name, parent process, and command-line executions from your
|
||||
endpoints.
|
||||
@@ -37,11 +38,12 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Active Directory Lateral Movement
|
||||
- WhisperGate
|
||||
- Industroyer2
|
||||
- CISA AA22-277A
|
||||
- Active Directory Lateral Movement
|
||||
- Prestige Ransomware
|
||||
- CISA AA22-277A
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Kerberoasting spn request with RC4 encryption
|
||||
id: 5cc67381-44fa-4111-8a37-7a230943f027
|
||||
version: 4
|
||||
date: '2022-02-09'
|
||||
date: '2023-04-14'
|
||||
author: Jose Hernandez, Patrick Bareiss, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,9 +30,10 @@ references:
|
||||
- https://www.hub.trimarcsecurity.com/post/trimarc-research-detecting-kerberoasting-activity
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
- Active Directory Kerberos Attacks
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Adding Crontab Using List Parameter
|
||||
id: 52f6d751-1fd4-4c74-a4c9-777ecfeb5c58
|
||||
version: 1
|
||||
date: '2022-04-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -31,8 +31,9 @@ tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Linux Privilege Escalation
|
||||
- Linux Persistence Techniques
|
||||
- Linux Living Off The Land
|
||||
- Data Destruction
|
||||
- Linux Persistence Techniques
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Data Destruction Command
|
||||
id: b11d3979-b2f7-411b-bb1a-bd00e642173b
|
||||
version: 1
|
||||
date: '2023-02-08'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 100
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux DD File Overwrite
|
||||
id: 9b6aae5e-8d85-11ec-b2ae-acde48001122
|
||||
version: 1
|
||||
date: '2022-02-14'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Deleting Critical Directory Using RM Command
|
||||
id: 33f89303-cc6f-49ad-921d-2eaea38a6f7a
|
||||
version: 1
|
||||
date: '2022-04-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,9 +31,9 @@ references:
|
||||
- https://cert.gov.ua/article/39518
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Deletion Of Cron Jobs
|
||||
id: 3b132a71-9335-4f33-9932-00bb4f6ac7e8
|
||||
version: 1
|
||||
date: '2022-04-12'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -39,6 +39,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AcidRain
|
||||
- Data Destruction
|
||||
asset_type: endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Deletion Of Init Daemon Script
|
||||
id: 729aab57-d26f-4156-b97f-ab8dda8f44b1
|
||||
version: 1
|
||||
date: '2022-04-12'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -40,6 +40,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AcidRain
|
||||
- Data Destruction
|
||||
asset_type: endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Deletion Of Services
|
||||
id: b509bbd3-0331-4aaa-8e4a-d2affe100af6
|
||||
version: 1
|
||||
date: '2023-02-15'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -40,8 +40,9 @@ references:
|
||||
- https://cert.gov.ua/article/3718487
|
||||
tags:
|
||||
analytic_story:
|
||||
- AcidRain
|
||||
- AwfulShred
|
||||
- AcidRain
|
||||
- Data Destruction
|
||||
asset_type: endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Disable Services
|
||||
id: f2e08a38-6689-4df4-ad8c-b51c16262316
|
||||
version: 1
|
||||
date: '2022-04-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,8 +29,9 @@ references:
|
||||
- https://cert.gov.ua/article/39518
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Hardware Addition SwapOff
|
||||
id: c1eea697-99ed-44c2-9b70-d8935464c499
|
||||
version: 1
|
||||
date: '2023-02-08'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -28,6 +28,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux High Frequency Of File Deletion In Boot Folder
|
||||
id: e27fbc5d-0445-4c4a-bc39-87f060d5c602
|
||||
version: 1
|
||||
date: '2022-04-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -39,8 +39,8 @@ references:
|
||||
- https://cert.gov.ua/article/39518
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
- Industroyer2
|
||||
asset_type: endpoint
|
||||
confidence: 80
|
||||
impact: 100
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux High Frequency Of File Deletion In Etc Folder
|
||||
id: 9d867448-2aff-4d07-876c-89409a752ff8
|
||||
version: 1
|
||||
date: '2022-04-12'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -39,6 +39,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AcidRain
|
||||
- Data Destruction
|
||||
asset_type: endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Impair Defenses Process Kill
|
||||
id: 435c6b33-adf9-47fe-be87-8e29fd6654f5
|
||||
version: 1
|
||||
date: '2023-02-08'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 30
|
||||
impact: 30
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Indicator Removal Clear Cache
|
||||
id: e0940505-0b73-4719-84e6-cb94c44a5245
|
||||
version: 1
|
||||
date: '2023-02-09'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Indicator Removal Service File Deletion
|
||||
id: 6c077f81-2a83-4537-afbc-0e62e3215d55
|
||||
version: 1
|
||||
date: '2023-02-08'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Java Spawning Shell
|
||||
id: 7b09db8a-5c20-11ec-9945-acde48001122
|
||||
version: 1
|
||||
date: '2021-12-13'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,9 +31,10 @@ references:
|
||||
- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Spring4Shell CVE-2022-22965
|
||||
- Hermetic Wiper
|
||||
- Log4Shell CVE-2021-44228
|
||||
- Spring4Shell CVE-2022-22965
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Service Restarted
|
||||
id: 084275ba-61b8-11ec-8d64-acde48001122
|
||||
version: 1
|
||||
date: '2021-12-20'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -33,10 +33,11 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1543/003/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Linux Privilege Escalation
|
||||
- Linux Persistence Techniques
|
||||
- Linux Living Off The Land
|
||||
- AwfulShred
|
||||
- Linux Privilege Escalation
|
||||
- Linux Living Off The Land
|
||||
- Data Destruction
|
||||
- Linux Persistence Techniques
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Shred Overwrite Command
|
||||
id: c1952cf1-643c-4965-82de-11c067cbae76
|
||||
version: 1
|
||||
date: '2022-04-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,9 +32,10 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Linux Privilege Escalation
|
||||
- Linux Persistence Techniques
|
||||
- AwfulShred
|
||||
- Linux Privilege Escalation
|
||||
- Data Destruction
|
||||
- Linux Persistence Techniques
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Stdout Redirection To Dev Null File
|
||||
id: de62b809-a04d-46b5-9a15-8298d330f0c8
|
||||
version: 1
|
||||
date: '2022-04-05'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- CyclopsBLink
|
||||
- Data Destruction
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Stop Services
|
||||
id: d05204a5-9f1c-4946-a7f3-4fa58d76d5fd
|
||||
version: 1
|
||||
date: '2022-04-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,8 +29,9 @@ references:
|
||||
- https://cert.gov.ua/article/39518
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux System Network Discovery
|
||||
id: 535cb214-8b47-11ec-a2c7-acde48001122
|
||||
version: 1
|
||||
date: '2022-02-11'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1016/T1016.md
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Network Discovery
|
||||
- Industroyer2
|
||||
asset_type: endpoint
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux System Reboot Via System Request Key
|
||||
id: e1912b58-ed9c-422c-bbb0-2dbc70398345
|
||||
version: 1
|
||||
date: '2023-02-08'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -32,6 +32,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Linux Unix Shell Enable All SysRq Functions
|
||||
id: e7a96937-3b58-4962-8dce-538e4763cf15
|
||||
version: 1
|
||||
date: '2023-02-08'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -32,6 +32,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- AwfulShred
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Logon Script Event Trigger Execution
|
||||
id: 4c38c264-1f74-11ec-b5fa-acde48001122
|
||||
version: 1
|
||||
date: '2021-09-27'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -27,9 +27,10 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1037/001/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Data Destruction
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
- Windows Persistence Techniques
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Malicious PowerShell Process With Obfuscation Techniques
|
||||
id: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4
|
||||
version: 5
|
||||
date: '2021-01-19'
|
||||
date: '2023-04-14'
|
||||
author: David Dorsey, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -27,8 +27,9 @@ known_false_positives: These characters might be legitimately on the command-lin
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: MSI Module Loaded by Non-System Binary
|
||||
id: ccb98a66-5851-11ec-b91c-acde48001122
|
||||
version: 1
|
||||
date: '2021-12-08'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -40,8 +40,9 @@ references:
|
||||
- https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/msi.dll%20Hijack%20(Methodology).ioc
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Overwriting Accessibility Binaries
|
||||
id: 13c2f6c3-10c5-4deb-9ba1-7c4460ebe4ae
|
||||
version: 4
|
||||
date: '2020-07-21'
|
||||
date: '2023-04-14'
|
||||
author: David Dorsey, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -28,8 +28,9 @@ known_false_positives: Microsoft may provide updates to these binaries. Verify t
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Ping Sleep Batch Command
|
||||
id: ce058d6c-79f2-11ec-b476-acde48001122
|
||||
version: 1
|
||||
date: '2022-01-20'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -31,6 +31,7 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Possible Lateral Movement PowerShell Spawn
|
||||
id: cb909b3e-512b-11ec-aa31-3e22fbd008af
|
||||
version: 1
|
||||
date: '2021-11-29'
|
||||
date: '2023-04-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -38,9 +38,10 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1543/003/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Active Directory Lateral Movement
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: PowerShell 4104 Hunting
|
||||
id: d6f2b006-0041-11ec-8885-acde48001122
|
||||
version: 3
|
||||
date: '2022-05-02'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -54,8 +54,9 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: PowerShell - Connect To Internet With Hidden Window
|
||||
id: ee18ed37-0802-4268-9435-b3b91aaa18db
|
||||
version: 8
|
||||
date: '2022-01-12'
|
||||
date: '2023-04-14'
|
||||
author: David Dorsey, Michael Haag Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -37,12 +37,13 @@ references:
|
||||
- https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
|
||||
- HAFNIUM Group
|
||||
- Log4Shell CVE-2021-44228
|
||||
- AgentTesla
|
||||
- HAFNIUM Group
|
||||
- Hermetic Wiper
|
||||
- Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns
|
||||
- Malicious PowerShell
|
||||
- Data Destruction
|
||||
- Log4Shell CVE-2021-44228
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: PowerShell Domain Enumeration
|
||||
id: e1866ce2-ca22-11eb-8e44-acde48001122
|
||||
version: 2
|
||||
date: '2022-02-25'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -35,8 +35,9 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Enable SMB1Protocol Feature
|
||||
id: afed80b2-d34b-11eb-a952-acde48001122
|
||||
version: 2
|
||||
date: '2022-02-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -24,9 +24,10 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Ransomware
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Execute COM Object
|
||||
id: 65711630-f9bf-11eb-8d72-acde48001122
|
||||
version: 2
|
||||
date: '2022-03-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -26,9 +26,10 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Ransomware
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 10
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Fileless Process Injection via GetProcAddress
|
||||
id: a26d9db4-c883-11eb-9d75-acde48001122
|
||||
version: 2
|
||||
date: '2022-02-25'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -39,8 +39,9 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Processing Stream Of Data
|
||||
id: 0d718b52-c9f1-11eb-bc61-acde48001122
|
||||
version: 2
|
||||
date: '2022-02-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,9 +30,10 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- AsyncRAT
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Remove Windows Defender Directory
|
||||
id: adf47620-79fa-11ec-b248-acde48001122
|
||||
version: 3
|
||||
date: '2022-05-02'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -24,6 +24,7 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Using memory As Backing Store
|
||||
id: c396a0c4-c9f2-11eb-b4f5-acde48001122
|
||||
version: 2
|
||||
date: '2022-03-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,8 +29,9 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Powershell Windows Defender Exclusion Commands
|
||||
id: 907ac95c-4dd9-11ec-ba2c-acde48001122
|
||||
version: 1
|
||||
date: '2021-11-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -28,11 +28,12 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Remcos
|
||||
- Windows Defense Evasion Tactics
|
||||
- WhisperGate
|
||||
- CISA AA22-320A
|
||||
- AgentTesla
|
||||
- Remcos
|
||||
- Windows Defense Evasion Tactics
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Print Processor Registry Autostart
|
||||
id: 1f5b68aa-2037-11ec-898e-acde48001122
|
||||
version: 1
|
||||
date: '2021-09-28'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -31,9 +31,10 @@ references:
|
||||
- https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Data Destruction
|
||||
- Windows Privilege Escalation
|
||||
- Hermetic Wiper
|
||||
- Windows Persistence Techniques
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Process Deleting Its Process File Path
|
||||
id: f7eda4bc-871c-11eb-b110-acde48001122
|
||||
version: 2
|
||||
date: '2022-02-18'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,8 +31,9 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Clop Ransomware
|
||||
- Remcos
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Remcos
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Recon AVProduct Through Pwh or WMI
|
||||
id: 28077620-c9f6-11eb-8785-acde48001122
|
||||
version: 2
|
||||
date: '2022-03-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,12 +31,13 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Ransomware
|
||||
- Malicious PowerShell
|
||||
- Qakbot
|
||||
- Windows Post-Exploitation
|
||||
- Hermetic Wiper
|
||||
- Ransomware
|
||||
- Prestige Ransomware
|
||||
- Malicious PowerShell
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Recon Using WMI Class
|
||||
id: 018c1972-ca07-11eb-9473-acde48001122
|
||||
version: 2
|
||||
date: '2022-10-10'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -36,12 +36,13 @@ references:
|
||||
- https://blogs.vmware.com/security/2022/10/lockbit-3-0-also-known-as-lockbit-black.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Industroyer2
|
||||
- Qakbot
|
||||
- LockBit Ransomware
|
||||
- AsyncRAT
|
||||
- Qakbot
|
||||
- Industroyer2
|
||||
- Hermetic Wiper
|
||||
- LockBit Ransomware
|
||||
- Malicious PowerShell
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 75
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Registry Keys Used For Privilege Escalation
|
||||
id: c9f4b923-f8af-4155-b697-1354f5bcbc5e
|
||||
version: 6
|
||||
date: '2022-11-14'
|
||||
date: '2023-04-14'
|
||||
author: Steven Dick, David Dorsey, Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -34,11 +34,12 @@ references:
|
||||
- https://blog.malwarebytes.com/101/2015/12/an-introduction-to-image-file-execution-options/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Suspicious Windows Registry Activities
|
||||
- Cloud Federated Credential Abuse
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Data Destruction
|
||||
- Suspicious Windows Registry Activities
|
||||
asset_type: Endpoint
|
||||
confidence: 95
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Regsvr32 Silent and Install Param Dll Loading
|
||||
id: f421c250-24e7-11ec-bc43-acde48001122
|
||||
version: 1
|
||||
date: '2021-10-04'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -31,12 +31,12 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1218/010/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Suspicious Regsvr32 Activity
|
||||
- Remcos
|
||||
- AsyncRAT
|
||||
- Hermetic Wiper
|
||||
- Living Off The Land
|
||||
- AsyncRAT
|
||||
- Data Destruction
|
||||
- Remcos
|
||||
- Suspicious Regsvr32 Activity
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Runas Execution in CommandLine
|
||||
id: 4807e716-43a4-11ec-a0e7-acde48001122
|
||||
version: 1
|
||||
date: '2021-11-12'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -31,8 +31,9 @@ references:
|
||||
- https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Privilege Escalation
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Schtasks Run Task On Demand
|
||||
id: bb37061e-af1f-11eb-a159-acde48001122
|
||||
version: 1
|
||||
date: '2021-05-07'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -27,10 +27,11 @@ references:
|
||||
- https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
|
||||
tags:
|
||||
analytic_story:
|
||||
- XMRig
|
||||
- Industroyer2
|
||||
- CISA AA22-257A
|
||||
- Qakbot
|
||||
- Industroyer2
|
||||
- XMRig
|
||||
- CISA AA22-257A
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Screensaver Event Trigger Execution
|
||||
id: 58cea3ec-1f6d-11ec-8560-acde48001122
|
||||
version: 1
|
||||
date: '2021-09-27'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,10 +30,11 @@ references:
|
||||
- https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
- Windows Persistence Techniques
|
||||
- Windows Registry Abuse
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 90
|
||||
impact: 80
|
||||
|
||||
+5
-4
@@ -1,7 +1,7 @@
|
||||
name: Set Default PowerShell Execution Policy To Unrestricted or Bypass
|
||||
id: c2590137-0b08-4985-9ec5-6ae23d92f63d
|
||||
version: 8
|
||||
date: '2022-11-14'
|
||||
date: '2023-04-14'
|
||||
author: Steven Dick, Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -33,10 +33,11 @@ known_false_positives: Administrators may attempt to change the default executio
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Credential Dumping
|
||||
- HAFNIUM Group
|
||||
- Hermetic Wiper
|
||||
- Credential Dumping
|
||||
- Malicious PowerShell
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious Process DNS Query Known Abuse Web Services
|
||||
id: 3cf0dc36-484d-11ec-a6bc-acde48001122
|
||||
version: 2
|
||||
date: '2022-01-18'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,8 +29,9 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Remcos
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
- Remcos
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious Process File Path
|
||||
id: 9be25988-ad82-11eb-a14f-acde48001122
|
||||
version: 1
|
||||
date: '2023-01-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -35,25 +35,25 @@ references:
|
||||
- https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Double Zero Destructor
|
||||
- XMRig
|
||||
- Remcos
|
||||
- WhisperGate
|
||||
- Hermetic Wiper
|
||||
- Industroyer2
|
||||
- DarkCrystal RAT
|
||||
- Brute Ratel C4
|
||||
- AgentTesla
|
||||
- Swift Slicer
|
||||
- Prestige Ransomware
|
||||
- Data Destruction
|
||||
- AsyncRAT
|
||||
- Brute Ratel C4
|
||||
- XMRig
|
||||
- LockBit Ransomware
|
||||
- WhisperGate
|
||||
- DarkCrystal RAT
|
||||
- Qakbot
|
||||
- Hermetic Wiper
|
||||
- Chaos Ransomware
|
||||
- Azorult
|
||||
- Double Zero Destructor
|
||||
- Industroyer2
|
||||
- IcedID
|
||||
- Trickbot
|
||||
- Azorult
|
||||
- Prestige Ransomware
|
||||
- Chaos Ransomware
|
||||
- LockBit Ransomware
|
||||
- AsyncRAT
|
||||
- Swift Slicer
|
||||
- Remcos
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious Process With Discord DNS Query
|
||||
id: 4d4332ae-792c-11ec-89c1-acde48001122
|
||||
version: 2
|
||||
date: '2022-06-01'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -27,6 +27,7 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Time Provider Persistence Registry
|
||||
id: 5ba382c4-2105-11ec-8d8f-acde48001122
|
||||
version: 3
|
||||
date: '2022-11-14'
|
||||
date: '2023-04-14'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -34,10 +34,11 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1547/003/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Windows Persistence Techniques
|
||||
- Windows Privilege Escalation
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
- Windows Privilege Escalation
|
||||
- Windows Persistence Techniques
|
||||
- Windows Registry Abuse
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Unloading AMSI via Reflection
|
||||
id: a21e3484-c94d-11eb-b55b-acde48001122
|
||||
version: 1
|
||||
date: '2021-06-09'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -37,8 +37,9 @@ references:
|
||||
- https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: W3WP Spawning Shell
|
||||
id: 0f03423c-7c6a-11eb-bc47-acde48001122
|
||||
version: 2
|
||||
date: '2021-03-03'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,12 +36,13 @@ references:
|
||||
- https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- HAFNIUM Group
|
||||
- CISA AA22-264A
|
||||
- Hermetic Wiper
|
||||
- ProxyNotShell
|
||||
- ProxyShell
|
||||
- CISA AA22-257A
|
||||
- ProxyNotShell
|
||||
- CISA AA22-264A
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
cve:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Data Destruction Recursive Exec Files Deletion
|
||||
id: 3596a799-6320-4a2f-8772-a9e98ddb2960
|
||||
version: 1
|
||||
date: '2023-02-02'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -30,6 +30,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Swift Slicer
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
+2
-1
@@ -1,7 +1,7 @@
|
||||
name: Windows Deleted Registry By A Non Critical Process File Path
|
||||
id: 15e70689-f55b-489e-8a80-6d0cd6d8aad2
|
||||
version: 2
|
||||
date: '2022-11-14'
|
||||
date: '2023-04-14'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -35,6 +35,7 @@ references:
|
||||
- https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Double Zero Destructor
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Disable Memory Crash Dump
|
||||
id: 59e54602-9680-11ec-a8a6-acde48001122
|
||||
version: 1
|
||||
date: '2022-02-25'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -36,10 +36,10 @@ references:
|
||||
- https://docs.microsoft.com/en-us/troubleshoot/windows-server/performance/memory-dump-file-options
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Ransomware
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows DotNet Binary in Non Standard Path
|
||||
id: fddf3b56-7933-11ec-98a6-acde48001122
|
||||
version: 1
|
||||
date: '2022-01-19'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -39,9 +39,10 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Masquerading - Rename System Utilities
|
||||
- Unusual Processes
|
||||
- Ransomware
|
||||
- Unusual Processes
|
||||
- Signed Binary Proxy Execution InstallUtil
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows File Without Extension In Critical Folder
|
||||
id: 0dbcac64-963c-11ec-bf04-acde48001122
|
||||
version: 1
|
||||
date: '2022-02-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Hidden Schedule Task Settings
|
||||
id: 0b730470-5fe8-4b13-93a7-fe0ad014d0cc
|
||||
version: 1
|
||||
date: '2022-04-26'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -25,9 +25,10 @@ references:
|
||||
- https://cert.gov.ua/article/39518
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Active Directory Discovery
|
||||
- CISA AA22-257A
|
||||
- Active Directory Discovery
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows High File Deletion Frequency
|
||||
id: 45b125c4-866f-11eb-a95a-acde48001122
|
||||
version: 1
|
||||
date: '2021-03-16'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -29,9 +29,10 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Clop Ransomware
|
||||
- WhisperGate
|
||||
- DarkCrystal RAT
|
||||
- Swift Slicer
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows InstallUtil in Non Standard Path
|
||||
id: dcf74b22-7933-11ec-857c-acde48001122
|
||||
version: 1
|
||||
date: '2022-01-19'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -34,11 +34,12 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Masquerading - Rename System Utilities
|
||||
- Unusual Processes
|
||||
- Ransomware
|
||||
- Unusual Processes
|
||||
- Signed Binary Proxy Execution InstallUtil
|
||||
- WhisperGate
|
||||
- Living Off The Land
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 70
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Linked Policies In ADSI Discovery
|
||||
id: 510ea428-4731-4d2f-8829-a28293e427aa
|
||||
version: 1
|
||||
date: '2022-04-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -25,8 +25,9 @@ references:
|
||||
- https://medium.com/@pentesttas/discover-hidden-gpo-s-on-active-directory-using-ps-adsi-a284b6814c81
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
- Active Directory Discovery
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Modify Show Compress Color And Info Tip Registry
|
||||
id: b7548c2e-9a10-11ec-99e3-acde48001122
|
||||
version: 2
|
||||
date: '2022-11-14'
|
||||
date: '2023-04-14'
|
||||
author: Steven Dick, Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -37,8 +37,8 @@ tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Windows Defense Evasion Tactics
|
||||
- Hermetic Wiper
|
||||
- Windows Registry Abuse
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows NirSoft AdvancedRun
|
||||
id: bb4f3090-7ae4-11ec-897f-acde48001122
|
||||
version: 1
|
||||
date: '2022-01-21'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,8 +31,9 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Unusual Processes
|
||||
- Ransomware
|
||||
- Unusual Processes
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows NirSoft Utilities
|
||||
id: 5b2f4596-7d4c-11ec-88a7-acde48001122
|
||||
version: 1
|
||||
date: '2022-01-24'
|
||||
date: '2023-04-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -29,6 +29,7 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Processes Killed By Industroyer2 Malware
|
||||
id: d8bea5ca-9d4a-4249-8b56-64a619109835
|
||||
version: 1
|
||||
date: '2022-04-22'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -26,6 +26,7 @@ references:
|
||||
- https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
confidence: 60
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Raw Access To Disk Volume Partition
|
||||
id: a85aa37e-9647-11ec-90c5-acde48001122
|
||||
version: 1
|
||||
date: '2022-02-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -27,10 +27,10 @@ references:
|
||||
- https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Caddy Wiper
|
||||
- Data Destruction
|
||||
- Hermetic Wiper
|
||||
- CISA AA22-264A
|
||||
- Data Destruction
|
||||
- Caddy Wiper
|
||||
- Hermetic Wiper
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Raw Access To Master Boot Record Drive
|
||||
id: 7b83f666-900c-11ec-a2d9-acde48001122
|
||||
version: 1
|
||||
date: '2022-02-17'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -29,11 +29,11 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Caddy Wiper
|
||||
- WhisperGate
|
||||
- Hermetic Wiper
|
||||
- CISA AA22-264A
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 90
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Root Domain linked policies Discovery
|
||||
id: 80ffaede-1f12-49d5-a86e-b4b599b68b3c
|
||||
version: 1
|
||||
date: '2022-04-25'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -24,8 +24,9 @@ references:
|
||||
- https://medium.com/@pentesttas/discover-hidden-gpo-s-on-active-directory-using-ps-adsi-a284b6814c81
|
||||
tags:
|
||||
analytic_story:
|
||||
- Industroyer2
|
||||
- Data Destruction
|
||||
- Active Directory Discovery
|
||||
- Industroyer2
|
||||
asset_type: Endpoint
|
||||
confidence: 50
|
||||
impact: 50
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Terminating Lsass Process
|
||||
id: 7ab3c319-a4e7-4211-9e8c-40a049d0dba6
|
||||
version: 1
|
||||
date: '2022-03-28'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -33,6 +33,7 @@ references:
|
||||
- https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Destruction
|
||||
- Double Zero Destructor
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: WMI Recon Running Process Or Services
|
||||
id: b5cd5526-cce7-11eb-b3bd-acde48001122
|
||||
version: 2
|
||||
date: '2022-05-02'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -28,8 +28,9 @@ references:
|
||||
- https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Hermetic Wiper
|
||||
- Malicious PowerShell
|
||||
- Hermetic Wiper
|
||||
- Data Destruction
|
||||
asset_type: Endpoint
|
||||
confidence: 100
|
||||
impact: 20
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Wscript Or Cscript Suspicious Child Process
|
||||
id: 1f35e1da-267b-11ec-90a9-acde48001122
|
||||
version: 1
|
||||
date: '2021-10-06'
|
||||
date: '2023-04-14'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -31,9 +31,10 @@ references:
|
||||
- https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
|
||||
tags:
|
||||
analytic_story:
|
||||
- FIN7
|
||||
- Remcos
|
||||
- FIN7
|
||||
- Unusual Processes
|
||||
- Data Destruction
|
||||
- WhisperGate
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
|
||||
@@ -1,16 +1,29 @@
|
||||
name: Data Destruction
|
||||
id: 4ae5c0d1-cebd-47d1-bfce-71bf096e38aa
|
||||
version: 1
|
||||
date: '2022-02-14'
|
||||
date: '2023-04-06'
|
||||
author: Teoderick Contreras, Splunk
|
||||
description: Leverage searches that allow you to detect and investigate unusual activities
|
||||
that might relate to the data destruction, including deleting files, overwriting files, wiping disk and encrypting files.
|
||||
narrative: Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption
|
||||
is the goal.
|
||||
description: Leverage searches that allow you to detect and investigate unusual activities that might relate to the data destruction,
|
||||
including deleting files, overwriting files, wiping disk and unrecoverable file encryption. This analytic story may cover several
|
||||
known activities related to malware implants used in geo-political war to wipe disks or files to interrupt the network-wide operation
|
||||
of a targeted organization. Analytics can detect the behavior of "DoubleZero Destructor", "CaddyWiper", "AcidRain", "AwfulShred",
|
||||
"Hermetic Wiper", "Swift Slicer", "Whisper Gate" and many more.
|
||||
narrative: Adversaries may partially or completely overwrite the contents of a storage device rendering the data irrecoverable through
|
||||
the storage interface or using 3rd party drivers to directly access disk content like Master Boot Record to wipe it.
|
||||
Some of these attacks were seen in geo-political war to impair the operation of targeted organizations or to interrupt network-wide services.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1485/
|
||||
- https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/
|
||||
- https://www.picussecurity.com/blog/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware
|
||||
- https://www.splunk.com/en_us/blog/security/threat-advisory-strt-ta02-destructive-software.html
|
||||
- https://www.splunk.com/en_us/blog/security/detecting-hermeticwiper.html
|
||||
- https://www.splunk.com/en_us/blog/security/threat-update-doublezero-destructor.html
|
||||
- https://www.splunk.com/en_us/blog/security/threat-update-caddywiper.html
|
||||
- https://www.splunk.com/en_us/blog/security/strt-ta03-cpe-destructive-software.html
|
||||
- https://www.splunk.com/en_us/blog/security/threat-update-cyclopsblink.html
|
||||
- https://www.splunk.com/en_us/blog/security/threat-update-acidrain-wiper.html
|
||||
- https://www.splunk.com/en_us/blog/security/threat-update-industroyer2.html
|
||||
- https://www.splunk.com/en_us/blog/security/threat-advisory-swiftslicer-wiper-strt-ta03.html
|
||||
tags:
|
||||
analytic_story: Data Destruction
|
||||
category:
|
||||
|
||||
Reference in New Issue
Block a user