diff --git a/detections/application/email_attachments_with_lots_of_spaces.yml b/detections/application/email_attachments_with_lots_of_spaces.yml index aa18cf785c..34fd4ab748 100644 --- a/detections/application/email_attachments_with_lots_of_spaces.yml +++ b/detections/application/email_attachments_with_lots_of_spaces.yml @@ -1,7 +1,7 @@ name: Email Attachments With Lots Of Spaces id: 56e877a6-1455-4479-ada6-0550dc1e22f8 version: 2 -date: '2017-09-19' +date: '2023-04-14' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -32,8 +32,9 @@ known_false_positives: None at this time references: [] tags: analytic_story: - - Hermetic Wiper + - Data Destruction - 'Emotet Malware DHS Report TA18-201A ' + - Hermetic Wiper - Suspicious Emails asset_type: Endpoint confidence: 50 diff --git a/detections/application/suspicious_email_attachment_extensions.yml b/detections/application/suspicious_email_attachment_extensions.yml index d11c100e7c..fc76b080cb 100644 --- a/detections/application/suspicious_email_attachment_extensions.yml +++ b/detections/application/suspicious_email_attachment_extensions.yml @@ -1,7 +1,7 @@ name: Suspicious Email Attachment Extensions id: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084 version: 3 -date: '2020-07-22' +date: '2023-04-14' author: David Dorsey, Splunk status: experimental type: Anomaly @@ -29,8 +29,9 @@ known_false_positives: None identified references: [] tags: analytic_story: - - Hermetic Wiper + - Data Destruction - 'Emotet Malware DHS Report TA18-201A ' + - Hermetic Wiper - Suspicious Emails asset_type: Endpoint confidence: 50 diff --git a/detections/endpoint/active_setup_registry_autostart.yml b/detections/endpoint/active_setup_registry_autostart.yml index 700eadc550..8a8f458623 100644 --- a/detections/endpoint/active_setup_registry_autostart.yml +++ b/detections/endpoint/active_setup_registry_autostart.yml @@ -1,7 +1,7 @@ name: Active Setup Registry Autostart id: f64579c0-203f-11ec-abcc-acde48001122 version: 3 -date: '2022-11-14' +date: '2023-04-14' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -36,9 +36,10 @@ references: - https://attack.mitre.org/techniques/T1547/014/ tags: analytic_story: - - Windows Persistence Techniques + - Data Destruction - Windows Privilege Escalation - Hermetic Wiper + - Windows Persistence Techniques asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/add_or_set_windows_defender_exclusion.yml b/detections/endpoint/add_or_set_windows_defender_exclusion.yml index 0899b8f266..cd9ae227df 100644 --- a/detections/endpoint/add_or_set_windows_defender_exclusion.yml +++ b/detections/endpoint/add_or_set_windows_defender_exclusion.yml @@ -1,7 +1,7 @@ name: Add or Set Windows Defender Exclusion id: 773b66fe-4dd9-11ec-8289-acde48001122 version: 1 -date: '2021-11-25' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -32,11 +32,12 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Remcos - - Windows Defense Evasion Tactics - - WhisperGate - CISA AA22-320A - AgentTesla + - Remcos + - Windows Defense Evasion Tactics + - Data Destruction + - WhisperGate asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/adsisearcher_account_discovery.yml b/detections/endpoint/adsisearcher_account_discovery.yml index 2755f509b4..778f857b56 100644 --- a/detections/endpoint/adsisearcher_account_discovery.yml +++ b/detections/endpoint/adsisearcher_account_discovery.yml @@ -1,7 +1,7 @@ name: AdsiSearcher Account Discovery id: de7fcadc-04f3-11ec-a241-acde48001122 version: 2 -date: '2022-11-13' +date: '2023-04-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -25,8 +25,9 @@ references: - https://devblogs.microsoft.com/scripting/use-the-powershell-adsisearcher-type-accelerator-to-search-active-directory/ tags: analytic_story: - - Industroyer2 + - Data Destruction - Active Directory Discovery + - Industroyer2 asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/any_powershell_downloadfile.yml b/detections/endpoint/any_powershell_downloadfile.yml index c612155fe6..e20278567b 100644 --- a/detections/endpoint/any_powershell_downloadfile.yml +++ b/detections/endpoint/any_powershell_downloadfile.yml @@ -1,7 +1,7 @@ name: Any Powershell DownloadFile id: 1a93b7ea-7af7-11eb-adb5-acde48001122 version: 3 -date: '2022-04-07' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -32,11 +32,12 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md tags: analytic_story: + - DarkCrystal RAT + - Ingress Tool Transfer - Hermetic Wiper - Malicious PowerShell - - Ingress Tool Transfer + - Data Destruction - Log4Shell CVE-2021-44228 - - DarkCrystal RAT asset_type: Endpoint confidence: 70 cve: diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index 1250aac0ff..c5aa104ec5 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -1,7 +1,7 @@ name: Attempt To Stop Security Service id: c8e349c6-b97c-486e-8949-bd7bcd1f3910 version: 4 -date: '2020-07-21' +date: '2023-04-14' author: Rico Valdez, Splunk status: production type: TTP @@ -29,10 +29,11 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Disabling Security Tools - - Trickbot - - WhisperGate - Azorult + - Trickbot + - Disabling Security Tools + - Data Destruction + - WhisperGate asset_type: Endpoint confidence: 50 impact: 40 diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index f80b07ca94..0e536b8a61 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -1,7 +1,7 @@ name: Attempted Credential Dump From Registry via Reg exe id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911 version: 7 -date: '2022-11-15' +date: '2023-04-14' author: Patrick Bareiss, Splunk status: production type: TTP @@ -28,10 +28,11 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1003.002/T1003.002.md#atomic-test-1---registry-dump-of-sam-creds-and-secrets tags: analytic_story: + - Industroyer2 + - Windows Registry Abuse - Credential Dumping - DarkSide Ransomware - - Windows Registry Abuse - - Industroyer2 + - Data Destruction asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/change_default_file_association.yml b/detections/endpoint/change_default_file_association.yml index f735f73064..53cbe05a4e 100644 --- a/detections/endpoint/change_default_file_association.yml +++ b/detections/endpoint/change_default_file_association.yml @@ -1,7 +1,7 @@ name: Change Default File Association id: 462d17d8-1f71-11ec-ad07-acde48001122 version: 1 -date: '2021-09-27' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -29,11 +29,12 @@ references: - https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features tags: analytic_story: - - Windows Persistence Techniques - - Windows Privilege Escalation - - Windows Registry Abuse - Hermetic Wiper + - Windows Registry Abuse - Prestige Ransomware + - Windows Privilege Escalation + - Windows Persistence Techniques + - Data Destruction asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/child_processes_of_spoolsv_exe.yml b/detections/endpoint/child_processes_of_spoolsv_exe.yml index 3e2e4253ff..07dbf99066 100644 --- a/detections/endpoint/child_processes_of_spoolsv_exe.yml +++ b/detections/endpoint/child_processes_of_spoolsv_exe.yml @@ -1,7 +1,7 @@ name: Child Processes of Spoolsv exe id: aa0c4aeb-5b18-41c4-8c07-f1442d7599df version: 3 -date: '2020-03-16' +date: '2023-04-14' author: Rico Valdez, Splunk status: experimental type: TTP @@ -28,8 +28,9 @@ known_false_positives: Some legitimate printer-related processes may show up as references: [] tags: analytic_story: - - Windows Privilege Escalation + - Data Destruction - Hermetic Wiper + - Windows Privilege Escalation asset_type: Endpoint confidence: 50 cve: diff --git a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml index 2d2e5508d7..0faa517232 100644 --- a/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml +++ b/detections/endpoint/detect_empire_with_powershell_script_block_logging.yml @@ -1,7 +1,7 @@ name: Detect Empire with PowerShell Script Block Logging id: bc1dc6b8-c954-11eb-bade-acde48001122 version: 2 -date: '2022-02-24' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -40,8 +40,9 @@ references: - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 90 impact: 90 diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index be784267c9..0bd9449319 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -1,7 +1,7 @@ name: Dump LSASS via comsvcs DLL id: 8943b567-f14d-4ee8-a0bb-2121d4ce3184 version: 2 -date: '2020-02-21' +date: '2023-04-14' author: Patrick Bareiss, Splunk status: production type: TTP @@ -24,14 +24,15 @@ references: - https://twitter.com/SBousseaden/status/1167417096374050817 tags: analytic_story: - - Credential Dumping - - Suspicious Rundll32 Activity - - HAFNIUM Group - - Living Off The Land - Industroyer2 - - CISA AA22-257A + - HAFNIUM Group - CISA AA22-264A - Prestige Ransomware + - Credential Dumping + - CISA AA22-257A + - Living Off The Land + - Suspicious Rundll32 Activity + - Data Destruction asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/etw_registry_disabled.yml b/detections/endpoint/etw_registry_disabled.yml index d92b8e3ed4..f794d71e3f 100644 --- a/detections/endpoint/etw_registry_disabled.yml +++ b/detections/endpoint/etw_registry_disabled.yml @@ -1,7 +1,7 @@ name: ETW Registry Disabled id: 8ed523ac-276b-11ec-ac39-acde48001122 version: 3 -date: '2022-11-14' +date: '2023-04-14' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -31,10 +31,11 @@ references: - https://gist.github.com/Cyb3rWard0g/a4a115fd3ab518a0e593525a379adee3 tags: analytic_story: - - Windows Persistence Techniques - - Windows Privilege Escalation - - Windows Registry Abuse - Hermetic Wiper + - Windows Privilege Escalation + - Windows Persistence Techniques + - Windows Registry Abuse + - Data Destruction asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml b/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml index e3fdbea933..cb79dd95fe 100644 --- a/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml +++ b/detections/endpoint/excessive_file_deletion_in_windefender_folder.yml @@ -1,7 +1,7 @@ name: Excessive File Deletion In WinDefender Folder id: b5baa09a-7a05-11ec-8da4-acde48001122 version: 1 -date: '2022-01-20' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -27,6 +27,7 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: + - Data Destruction - WhisperGate asset_type: Endpoint confidence: 50 diff --git a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml index 7980f93194..0425c497a8 100644 --- a/detections/endpoint/executable_file_written_in_administrative_smb_share.yml +++ b/detections/endpoint/executable_file_written_in_administrative_smb_share.yml @@ -1,7 +1,7 @@ name: Executable File Written in Administrative SMB Share id: f63c34fe-a435-11eb-935a-acde48001122 version: 2 -date: '2021-11-18' +date: '2023-04-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: TTP @@ -32,12 +32,12 @@ references: - https://whitehat.eu/incident-response-case-study-featuring-ryuk-and-trickbot-part-2/ tags: analytic_story: - - Data Destruction - - Active Directory Lateral Movement - - Trickbot - - Hermetic Wiper - Industroyer2 + - Active Directory Lateral Movement + - Hermetic Wiper + - Trickbot - Prestige Ransomware + - Data Destruction asset_type: Endpoint confidence: 100 impact: 70 diff --git a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml index b466192d20..6d1289b8dc 100644 --- a/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml +++ b/detections/endpoint/executables_or_script_creation_in_suspicious_path.yml @@ -1,7 +1,7 @@ name: Executables Or Script Creation In Suspicious Path id: a7e3f0f0-ae42-11eb-b245-acde48001122 version: 1 -date: '2021-10-06' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -37,24 +37,24 @@ references: - https://twitter.com/pr0xylife/status/1590394227758104576 tags: analytic_story: - - Double Zero Destructor - - Data Destruction - - XMRig - - Remcos - - WhisperGate - - Hermetic Wiper - - Industroyer2 - - Azorult - DarkCrystal RAT + - AsyncRAT + - Azorult - Brute Ratel C4 + - Double Zero Destructor + - Industroyer2 - AgentTesla - Qakbot - IcedID + - Remcos + - XMRig + - Hermetic Wiper - Trickbot - Chaos Ransomware - - LockBit Ransomware - - AsyncRAT - Swift Slicer + - LockBit Ransomware + - Data Destruction + - WhisperGate asset_type: Endpoint confidence: 50 impact: 40 diff --git a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml index b71e828e78..f13537da7d 100644 --- a/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml +++ b/detections/endpoint/impacket_lateral_movement_commandline_parameters.yml @@ -1,7 +1,7 @@ name: Impacket Lateral Movement Commandline Parameters id: 8ce07472-496f-11ec-ab3b-3e22fbd008af version: 3 -date: '2023-02-24' +date: '2023-04-14' author: Mauricio Velazco, Splunk status: production type: TTP @@ -15,11 +15,12 @@ description: This analytic looks for the presence of suspicious commandline para tools for lateral movement and remote code execution. data_source: - Sysmon Event ID 1 -search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe (Processes.process = "*/Q /c * \\\\127.0.0.1\\*$*" AND Processes.process IN ("*2>&1*","*2>&1*")) by Processes.dest Processes.user Processes.parent_process_name Processes.process_name Processes.process Processes.process_id Processes.parent_process_id - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `impacket_lateral_movement_commandline_parameters_filter`' +search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) + as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe + (Processes.process = "*/Q /c * \\\\127.0.0.1\\*$*" AND Processes.process IN ("*2>&1*","*2>&1*")) + by Processes.dest Processes.user Processes.parent_process_name Processes.process_name + Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `impacket_lateral_movement_commandline_parameters_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. @@ -37,11 +38,12 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Active Directory Lateral Movement - - WhisperGate - Industroyer2 - - CISA AA22-277A + - Active Directory Lateral Movement - Prestige Ransomware + - CISA AA22-277A + - Data Destruction + - WhisperGate asset_type: Endpoint confidence: 70 impact: 90 diff --git a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml index 1c62228bf6..09cb255ca7 100644 --- a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml +++ b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml @@ -1,7 +1,7 @@ name: Kerberoasting spn request with RC4 encryption id: 5cc67381-44fa-4111-8a37-7a230943f027 version: 4 -date: '2022-02-09' +date: '2023-04-14' author: Jose Hernandez, Patrick Bareiss, Mauricio Velazco, Splunk status: production type: TTP @@ -30,9 +30,10 @@ references: - https://www.hub.trimarcsecurity.com/post/trimarc-research-detecting-kerberoasting-activity tags: analytic_story: + - Data Destruction + - Hermetic Wiper - Windows Privilege Escalation - Active Directory Kerberos Attacks - - Hermetic Wiper asset_type: Endpoint confidence: 80 impact: 90 diff --git a/detections/endpoint/linux_adding_crontab_using_list_parameter.yml b/detections/endpoint/linux_adding_crontab_using_list_parameter.yml index 614de460d1..46d9e3e62f 100644 --- a/detections/endpoint/linux_adding_crontab_using_list_parameter.yml +++ b/detections/endpoint/linux_adding_crontab_using_list_parameter.yml @@ -1,7 +1,7 @@ name: Linux Adding Crontab Using List Parameter id: 52f6d751-1fd4-4c74-a4c9-777ecfeb5c58 version: 1 -date: '2022-04-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -31,8 +31,9 @@ tags: analytic_story: - Industroyer2 - Linux Privilege Escalation - - Linux Persistence Techniques - Linux Living Off The Land + - Data Destruction + - Linux Persistence Techniques asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/linux_data_destruction_command.yml b/detections/endpoint/linux_data_destruction_command.yml index ecab5a69a9..187250dd13 100644 --- a/detections/endpoint/linux_data_destruction_command.yml +++ b/detections/endpoint/linux_data_destruction_command.yml @@ -1,7 +1,7 @@ name: Linux Data Destruction Command id: b11d3979-b2f7-411b-bb1a-bd00e642173b version: 1 -date: '2023-02-08' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -30,6 +30,7 @@ references: tags: analytic_story: - AwfulShred + - Data Destruction asset_type: Endpoint confidence: 90 impact: 100 diff --git a/detections/endpoint/linux_dd_file_overwrite.yml b/detections/endpoint/linux_dd_file_overwrite.yml index b518eef7ea..deaa7cba46 100644 --- a/detections/endpoint/linux_dd_file_overwrite.yml +++ b/detections/endpoint/linux_dd_file_overwrite.yml @@ -1,7 +1,7 @@ name: Linux DD File Overwrite id: 9b6aae5e-8d85-11ec-b2ae-acde48001122 version: 1 -date: '2022-02-14' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP diff --git a/detections/endpoint/linux_deleting_critical_directory_using_rm_command.yml b/detections/endpoint/linux_deleting_critical_directory_using_rm_command.yml index be4917a2fe..a57e53a19f 100644 --- a/detections/endpoint/linux_deleting_critical_directory_using_rm_command.yml +++ b/detections/endpoint/linux_deleting_critical_directory_using_rm_command.yml @@ -1,7 +1,7 @@ name: Linux Deleting Critical Directory Using RM Command id: 33f89303-cc6f-49ad-921d-2eaea38a6f7a version: 1 -date: '2022-04-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -31,9 +31,9 @@ references: - https://cert.gov.ua/article/39518 tags: analytic_story: - - Industroyer2 - - Data Destruction - AwfulShred + - Data Destruction + - Industroyer2 asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/linux_deletion_of_cron_jobs.yml b/detections/endpoint/linux_deletion_of_cron_jobs.yml index 935df9abf7..e913a99722 100644 --- a/detections/endpoint/linux_deletion_of_cron_jobs.yml +++ b/detections/endpoint/linux_deletion_of_cron_jobs.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Cron Jobs id: 3b132a71-9335-4f33-9932-00bb4f6ac7e8 version: 1 -date: '2022-04-12' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -39,6 +39,7 @@ references: tags: analytic_story: - AcidRain + - Data Destruction asset_type: endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/linux_deletion_of_init_daemon_script.yml b/detections/endpoint/linux_deletion_of_init_daemon_script.yml index b4a66fcda9..101746595c 100644 --- a/detections/endpoint/linux_deletion_of_init_daemon_script.yml +++ b/detections/endpoint/linux_deletion_of_init_daemon_script.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Init Daemon Script id: 729aab57-d26f-4156-b97f-ab8dda8f44b1 version: 1 -date: '2022-04-12' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -40,6 +40,7 @@ references: tags: analytic_story: - AcidRain + - Data Destruction asset_type: endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/linux_deletion_of_services.yml b/detections/endpoint/linux_deletion_of_services.yml index 9cbf3637d8..840365bffa 100644 --- a/detections/endpoint/linux_deletion_of_services.yml +++ b/detections/endpoint/linux_deletion_of_services.yml @@ -1,7 +1,7 @@ name: Linux Deletion Of Services id: b509bbd3-0331-4aaa-8e4a-d2affe100af6 version: 1 -date: '2023-02-15' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -40,8 +40,9 @@ references: - https://cert.gov.ua/article/3718487 tags: analytic_story: - - AcidRain - AwfulShred + - AcidRain + - Data Destruction asset_type: endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/linux_disable_services.yml b/detections/endpoint/linux_disable_services.yml index a862152325..20bf9f5c6d 100644 --- a/detections/endpoint/linux_disable_services.yml +++ b/detections/endpoint/linux_disable_services.yml @@ -1,7 +1,7 @@ name: Linux Disable Services id: f2e08a38-6689-4df4-ad8c-b51c16262316 version: 1 -date: '2022-04-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -29,8 +29,9 @@ references: - https://cert.gov.ua/article/39518 tags: analytic_story: - - Industroyer2 - AwfulShred + - Data Destruction + - Industroyer2 asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/linux_hardware_addition_swapoff.yml b/detections/endpoint/linux_hardware_addition_swapoff.yml index 6305e9a1ae..0fb0b9eb7f 100644 --- a/detections/endpoint/linux_hardware_addition_swapoff.yml +++ b/detections/endpoint/linux_hardware_addition_swapoff.yml @@ -1,7 +1,7 @@ name: Linux Hardware Addition SwapOff id: c1eea697-99ed-44c2-9b70-d8935464c499 version: 1 -date: '2023-02-08' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -28,6 +28,7 @@ references: tags: analytic_story: - AwfulShred + - Data Destruction asset_type: Endpoint confidence: 60 impact: 60 diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml index dc5acb2fe0..a5e880b660 100644 --- a/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml +++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_boot_folder.yml @@ -1,7 +1,7 @@ name: Linux High Frequency Of File Deletion In Boot Folder id: e27fbc5d-0445-4c4a-bc39-87f060d5c602 version: 1 -date: '2022-04-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -39,8 +39,8 @@ references: - https://cert.gov.ua/article/39518 tags: analytic_story: - - Industroyer2 - Data Destruction + - Industroyer2 asset_type: endpoint confidence: 80 impact: 100 diff --git a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml index f10fa5366b..d1dbe4022e 100644 --- a/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml +++ b/detections/endpoint/linux_high_frequency_of_file_deletion_in_etc_folder.yml @@ -1,7 +1,7 @@ name: Linux High Frequency Of File Deletion In Etc Folder id: 9d867448-2aff-4d07-876c-89409a752ff8 version: 1 -date: '2022-04-12' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -39,6 +39,7 @@ references: tags: analytic_story: - AcidRain + - Data Destruction asset_type: endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/linux_impair_defenses_process_kill.yml b/detections/endpoint/linux_impair_defenses_process_kill.yml index 1ebd74767f..87d6109b3e 100644 --- a/detections/endpoint/linux_impair_defenses_process_kill.yml +++ b/detections/endpoint/linux_impair_defenses_process_kill.yml @@ -1,7 +1,7 @@ name: Linux Impair Defenses Process Kill id: 435c6b33-adf9-47fe-be87-8e29fd6654f5 version: 1 -date: '2023-02-08' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -31,6 +31,7 @@ references: tags: analytic_story: - AwfulShred + - Data Destruction asset_type: Endpoint confidence: 30 impact: 30 diff --git a/detections/endpoint/linux_indicator_removal_clear_cache.yml b/detections/endpoint/linux_indicator_removal_clear_cache.yml index ed902e1874..44fb1bdb27 100644 --- a/detections/endpoint/linux_indicator_removal_clear_cache.yml +++ b/detections/endpoint/linux_indicator_removal_clear_cache.yml @@ -1,7 +1,7 @@ name: Linux Indicator Removal Clear Cache id: e0940505-0b73-4719-84e6-cb94c44a5245 version: 1 -date: '2023-02-09' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -30,6 +30,7 @@ references: tags: analytic_story: - AwfulShred + - Data Destruction asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/linux_indicator_removal_service_file_deletion.yml b/detections/endpoint/linux_indicator_removal_service_file_deletion.yml index 4dbd17f446..05b1c5bd5f 100644 --- a/detections/endpoint/linux_indicator_removal_service_file_deletion.yml +++ b/detections/endpoint/linux_indicator_removal_service_file_deletion.yml @@ -1,7 +1,7 @@ name: Linux Indicator Removal Service File Deletion id: 6c077f81-2a83-4537-afbc-0e62e3215d55 version: 1 -date: '2023-02-08' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -31,6 +31,7 @@ references: tags: analytic_story: - AwfulShred + - Data Destruction asset_type: Endpoint confidence: 60 impact: 60 diff --git a/detections/endpoint/linux_java_spawning_shell.yml b/detections/endpoint/linux_java_spawning_shell.yml index f182ac6e16..5919541409 100644 --- a/detections/endpoint/linux_java_spawning_shell.yml +++ b/detections/endpoint/linux_java_spawning_shell.yml @@ -1,7 +1,7 @@ name: Linux Java Spawning Shell id: 7b09db8a-5c20-11ec-9945-acde48001122 version: 1 -date: '2021-12-13' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -31,9 +31,10 @@ references: - https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72 tags: analytic_story: + - Data Destruction + - Spring4Shell CVE-2022-22965 - Hermetic Wiper - Log4Shell CVE-2021-44228 - - Spring4Shell CVE-2022-22965 asset_type: Endpoint confidence: 50 cve: diff --git a/detections/endpoint/linux_service_restarted.yml b/detections/endpoint/linux_service_restarted.yml index ddea276b04..a1182439ee 100644 --- a/detections/endpoint/linux_service_restarted.yml +++ b/detections/endpoint/linux_service_restarted.yml @@ -1,7 +1,7 @@ name: Linux Service Restarted id: 084275ba-61b8-11ec-8d64-acde48001122 version: 1 -date: '2021-12-20' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -33,10 +33,11 @@ references: - https://attack.mitre.org/techniques/T1543/003/ tags: analytic_story: - - Linux Privilege Escalation - - Linux Persistence Techniques - - Linux Living Off The Land - AwfulShred + - Linux Privilege Escalation + - Linux Living Off The Land + - Data Destruction + - Linux Persistence Techniques asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/linux_shred_overwrite_command.yml b/detections/endpoint/linux_shred_overwrite_command.yml index 29304d89b7..70d6c63322 100644 --- a/detections/endpoint/linux_shred_overwrite_command.yml +++ b/detections/endpoint/linux_shred_overwrite_command.yml @@ -1,7 +1,7 @@ name: Linux Shred Overwrite Command id: c1952cf1-643c-4965-82de-11c067cbae76 version: 1 -date: '2022-04-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -32,9 +32,10 @@ references: tags: analytic_story: - Industroyer2 - - Linux Privilege Escalation - - Linux Persistence Techniques - AwfulShred + - Linux Privilege Escalation + - Data Destruction + - Linux Persistence Techniques asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml b/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml index 45b3ff75e8..63f81e93d2 100644 --- a/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml +++ b/detections/endpoint/linux_stdout_redirection_to_dev_null_file.yml @@ -1,7 +1,7 @@ name: Linux Stdout Redirection To Dev Null File id: de62b809-a04d-46b5-9a15-8298d330f0c8 version: 1 -date: '2022-04-05' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: experimental type: Anomaly @@ -30,6 +30,7 @@ references: tags: analytic_story: - CyclopsBLink + - Data Destruction - Industroyer2 asset_type: Endpoint confidence: 60 diff --git a/detections/endpoint/linux_stop_services.yml b/detections/endpoint/linux_stop_services.yml index e4e8057483..5f6f7c3fe3 100644 --- a/detections/endpoint/linux_stop_services.yml +++ b/detections/endpoint/linux_stop_services.yml @@ -1,7 +1,7 @@ name: Linux Stop Services id: d05204a5-9f1c-4946-a7f3-4fa58d76d5fd version: 1 -date: '2022-04-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -29,8 +29,9 @@ references: - https://cert.gov.ua/article/39518 tags: analytic_story: - - Industroyer2 - AwfulShred + - Data Destruction + - Industroyer2 asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/linux_system_network_discovery.yml b/detections/endpoint/linux_system_network_discovery.yml index 06e298657b..7902c25557 100644 --- a/detections/endpoint/linux_system_network_discovery.yml +++ b/detections/endpoint/linux_system_network_discovery.yml @@ -1,7 +1,7 @@ name: Linux System Network Discovery id: 535cb214-8b47-11ec-a2c7-acde48001122 version: 1 -date: '2022-02-11' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -30,6 +30,7 @@ references: - https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1016/T1016.md tags: analytic_story: + - Data Destruction - Network Discovery - Industroyer2 asset_type: endpoint diff --git a/detections/endpoint/linux_system_reboot_via_system_request_key.yml b/detections/endpoint/linux_system_reboot_via_system_request_key.yml index 25bddedee3..79863b79b4 100644 --- a/detections/endpoint/linux_system_reboot_via_system_request_key.yml +++ b/detections/endpoint/linux_system_reboot_via_system_request_key.yml @@ -1,7 +1,7 @@ name: Linux System Reboot Via System Request Key id: e1912b58-ed9c-422c-bbb0-2dbc70398345 version: 1 -date: '2023-02-08' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -32,6 +32,7 @@ references: tags: analytic_story: - AwfulShred + - Data Destruction asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml b/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml index af669d14a8..8aa8c974c2 100644 --- a/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml +++ b/detections/endpoint/linux_unix_shell_enable_all_sysrq_functions.yml @@ -1,7 +1,7 @@ name: Linux Unix Shell Enable All SysRq Functions id: e7a96937-3b58-4962-8dce-538e4763cf15 version: 1 -date: '2023-02-08' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -32,6 +32,7 @@ references: tags: analytic_story: - AwfulShred + - Data Destruction asset_type: Endpoint confidence: 60 impact: 60 diff --git a/detections/endpoint/logon_script_event_trigger_execution.yml b/detections/endpoint/logon_script_event_trigger_execution.yml index 64ba82fa51..96354f8729 100644 --- a/detections/endpoint/logon_script_event_trigger_execution.yml +++ b/detections/endpoint/logon_script_event_trigger_execution.yml @@ -1,7 +1,7 @@ name: Logon Script Event Trigger Execution id: 4c38c264-1f74-11ec-b5fa-acde48001122 version: 1 -date: '2021-09-27' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -27,9 +27,10 @@ references: - https://attack.mitre.org/techniques/T1037/001/ tags: analytic_story: - - Windows Persistence Techniques + - Data Destruction - Windows Privilege Escalation - Hermetic Wiper + - Windows Persistence Techniques asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml index 4843be850d..ec019553b4 100644 --- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml +++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml @@ -1,7 +1,7 @@ name: Malicious PowerShell Process With Obfuscation Techniques id: cde75cf6-3c7a-4dd6-af01-27cdb4511fd4 version: 5 -date: '2021-01-19' +date: '2023-04-14' author: David Dorsey, Splunk status: production type: TTP @@ -27,8 +27,9 @@ known_false_positives: These characters might be legitimately on the command-lin references: [] tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 60 impact: 70 diff --git a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml index dd3e1dfc1b..f8f2e94605 100644 --- a/detections/endpoint/msi_module_loaded_by_non_system_binary.yml +++ b/detections/endpoint/msi_module_loaded_by_non_system_binary.yml @@ -1,7 +1,7 @@ name: MSI Module Loaded by Non-System Binary id: ccb98a66-5851-11ec-b91c-acde48001122 version: 1 -date: '2021-12-08' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: Hunting @@ -40,8 +40,9 @@ references: - https://github.com/mandiant/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/msi.dll%20Hijack%20(Methodology).ioc tags: analytic_story: - - Windows Privilege Escalation + - Data Destruction - Hermetic Wiper + - Windows Privilege Escalation asset_type: Endpoint confidence: 70 cve: diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index 7ab35ce1f9..c0dc52acf1 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -1,7 +1,7 @@ name: Overwriting Accessibility Binaries id: 13c2f6c3-10c5-4deb-9ba1-7c4460ebe4ae version: 4 -date: '2020-07-21' +date: '2023-04-14' author: David Dorsey, Splunk status: production type: TTP @@ -28,8 +28,9 @@ known_false_positives: Microsoft may provide updates to these binaries. Verify t references: [] tags: analytic_story: - - Windows Privilege Escalation + - Data Destruction - Hermetic Wiper + - Windows Privilege Escalation asset_type: Endpoint confidence: 90 impact: 80 diff --git a/detections/endpoint/ping_sleep_batch_command.yml b/detections/endpoint/ping_sleep_batch_command.yml index 51502eca9b..a75912c59c 100644 --- a/detections/endpoint/ping_sleep_batch_command.yml +++ b/detections/endpoint/ping_sleep_batch_command.yml @@ -1,7 +1,7 @@ name: Ping Sleep Batch Command id: ce058d6c-79f2-11ec-b476-acde48001122 version: 1 -date: '2022-01-20' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -31,6 +31,7 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: + - Data Destruction - WhisperGate asset_type: Endpoint confidence: 60 diff --git a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml index cd5ed09145..f04f4f1268 100644 --- a/detections/endpoint/possible_lateral_movement_powershell_spawn.yml +++ b/detections/endpoint/possible_lateral_movement_powershell_spawn.yml @@ -1,7 +1,7 @@ name: Possible Lateral Movement PowerShell Spawn id: cb909b3e-512b-11ec-aa31-3e22fbd008af version: 1 -date: '2021-11-29' +date: '2023-04-14' author: Mauricio Velazco, Splunk status: production type: TTP @@ -38,9 +38,10 @@ references: - https://attack.mitre.org/techniques/T1543/003/ tags: analytic_story: - - Hermetic Wiper - Active Directory Lateral Movement - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 50 impact: 90 diff --git a/detections/endpoint/powershell_4104_hunting.yml b/detections/endpoint/powershell_4104_hunting.yml index 1baa03e64f..ae77734430 100644 --- a/detections/endpoint/powershell_4104_hunting.yml +++ b/detections/endpoint/powershell_4104_hunting.yml @@ -1,7 +1,7 @@ name: PowerShell 4104 Hunting id: d6f2b006-0041-11ec-8885-acde48001122 version: 3 -date: '2022-05-02' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: Hunting @@ -54,8 +54,9 @@ references: - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml b/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml index c037b34d52..b434eb0b62 100644 --- a/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml @@ -1,7 +1,7 @@ name: PowerShell - Connect To Internet With Hidden Window id: ee18ed37-0802-4268-9435-b3b91aaa18db version: 8 -date: '2022-01-12' +date: '2023-04-14' author: David Dorsey, Michael Haag Splunk status: production type: Hunting @@ -37,12 +37,13 @@ references: - https://blog.netlab.360.com/ten-families-of-malicious-samples-are-spreading-using-the-log4j2-vulnerability-now/ tags: analytic_story: - - Hermetic Wiper - - Malicious PowerShell - - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns - - HAFNIUM Group - - Log4Shell CVE-2021-44228 - AgentTesla + - HAFNIUM Group + - Hermetic Wiper + - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns + - Malicious PowerShell + - Data Destruction + - Log4Shell CVE-2021-44228 asset_type: Endpoint confidence: 90 cve: diff --git a/detections/endpoint/powershell_domain_enumeration.yml b/detections/endpoint/powershell_domain_enumeration.yml index 6c657e0f34..9c40d3d817 100644 --- a/detections/endpoint/powershell_domain_enumeration.yml +++ b/detections/endpoint/powershell_domain_enumeration.yml @@ -1,7 +1,7 @@ name: PowerShell Domain Enumeration id: e1866ce2-ca22-11eb-8e44-acde48001122 version: 2 -date: '2022-02-25' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -35,8 +35,9 @@ references: - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 70 impact: 60 diff --git a/detections/endpoint/powershell_enable_smb1protocol_feature.yml b/detections/endpoint/powershell_enable_smb1protocol_feature.yml index cf5e8883b8..83a13df36b 100644 --- a/detections/endpoint/powershell_enable_smb1protocol_feature.yml +++ b/detections/endpoint/powershell_enable_smb1protocol_feature.yml @@ -1,7 +1,7 @@ name: Powershell Enable SMB1Protocol Feature id: afed80b2-d34b-11eb-a952-acde48001122 version: 2 -date: '2022-02-25' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -24,9 +24,10 @@ references: - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html tags: analytic_story: - - Hermetic Wiper - - Malicious PowerShell - Ransomware + - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/powershell_execute_com_object.yml b/detections/endpoint/powershell_execute_com_object.yml index 90f4e2570a..1639b34fef 100644 --- a/detections/endpoint/powershell_execute_com_object.yml +++ b/detections/endpoint/powershell_execute_com_object.yml @@ -1,7 +1,7 @@ name: Powershell Execute COM Object id: 65711630-f9bf-11eb-8d72-acde48001122 version: 2 -date: '2022-03-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -26,9 +26,10 @@ references: - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html tags: analytic_story: - - Hermetic Wiper - - Malicious PowerShell - Ransomware + - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 50 impact: 10 diff --git a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml index d1332a242d..ed2f12552f 100644 --- a/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml +++ b/detections/endpoint/powershell_fileless_process_injection_via_getprocaddress.yml @@ -1,7 +1,7 @@ name: Powershell Fileless Process Injection via GetProcAddress id: a26d9db4-c883-11eb-9d75-acde48001122 version: 2 -date: '2022-02-25' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -39,8 +39,9 @@ references: - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 80 impact: 60 diff --git a/detections/endpoint/powershell_processing_stream_of_data.yml b/detections/endpoint/powershell_processing_stream_of_data.yml index f8182b87f9..b3506a2b45 100644 --- a/detections/endpoint/powershell_processing_stream_of_data.yml +++ b/detections/endpoint/powershell_processing_stream_of_data.yml @@ -1,7 +1,7 @@ name: Powershell Processing Stream Of Data id: 0d718b52-c9f1-11eb-bc61-acde48001122 version: 2 -date: '2022-02-25' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -30,9 +30,10 @@ references: - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell - AsyncRAT + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 80 impact: 50 diff --git a/detections/endpoint/powershell_remove_windows_defender_directory.yml b/detections/endpoint/powershell_remove_windows_defender_directory.yml index 816a41d88f..fbc63a2bab 100644 --- a/detections/endpoint/powershell_remove_windows_defender_directory.yml +++ b/detections/endpoint/powershell_remove_windows_defender_directory.yml @@ -1,7 +1,7 @@ name: Powershell Remove Windows Defender Directory id: adf47620-79fa-11ec-b248-acde48001122 version: 3 -date: '2022-05-02' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -24,6 +24,7 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: + - Data Destruction - WhisperGate asset_type: Endpoint confidence: 90 diff --git a/detections/endpoint/powershell_using_memory_as_backing_store.yml b/detections/endpoint/powershell_using_memory_as_backing_store.yml index 317812b0b1..b4b75a94fc 100644 --- a/detections/endpoint/powershell_using_memory_as_backing_store.yml +++ b/detections/endpoint/powershell_using_memory_as_backing_store.yml @@ -1,7 +1,7 @@ name: Powershell Using memory As Backing Store id: c396a0c4-c9f2-11eb-b4f5-acde48001122 version: 2 -date: '2022-03-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -29,8 +29,9 @@ references: - https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 80 impact: 50 diff --git a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml index 3f6064d85b..a58d983c17 100644 --- a/detections/endpoint/powershell_windows_defender_exclusion_commands.yml +++ b/detections/endpoint/powershell_windows_defender_exclusion_commands.yml @@ -1,7 +1,7 @@ name: Powershell Windows Defender Exclusion Commands id: 907ac95c-4dd9-11ec-ba2c-acde48001122 version: 1 -date: '2021-11-25' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -28,11 +28,12 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Remcos - - Windows Defense Evasion Tactics - - WhisperGate - CISA AA22-320A - AgentTesla + - Remcos + - Windows Defense Evasion Tactics + - Data Destruction + - WhisperGate asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/print_processor_registry_autostart.yml b/detections/endpoint/print_processor_registry_autostart.yml index c7a0550b04..6255528150 100644 --- a/detections/endpoint/print_processor_registry_autostart.yml +++ b/detections/endpoint/print_processor_registry_autostart.yml @@ -1,7 +1,7 @@ name: Print Processor Registry Autostart id: 1f5b68aa-2037-11ec-898e-acde48001122 version: 1 -date: '2021-09-28' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: experimental type: TTP @@ -31,9 +31,10 @@ references: - https://www.welivesecurity.com/2020/05/21/no-game-over-winnti-group/ tags: analytic_story: - - Windows Persistence Techniques + - Data Destruction - Windows Privilege Escalation - Hermetic Wiper + - Windows Persistence Techniques asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/process_deleting_its_process_file_path.yml b/detections/endpoint/process_deleting_its_process_file_path.yml index f1fa2bb256..babbb462ed 100644 --- a/detections/endpoint/process_deleting_its_process_file_path.yml +++ b/detections/endpoint/process_deleting_its_process_file_path.yml @@ -1,7 +1,7 @@ name: Process Deleting Its Process File Path id: f7eda4bc-871c-11eb-b110-acde48001122 version: 2 -date: '2022-02-18' +date: '2023-04-14' author: Teoderick Contreras status: production type: TTP @@ -31,8 +31,9 @@ references: tags: analytic_story: - Clop Ransomware - - Remcos + - Data Destruction - WhisperGate + - Remcos asset_type: Endpoint confidence: 100 impact: 60 diff --git a/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml b/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml index fe55694cb6..2af51f76ca 100644 --- a/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml +++ b/detections/endpoint/recon_avproduct_through_pwh_or_wmi.yml @@ -1,7 +1,7 @@ name: Recon AVProduct Through Pwh or WMI id: 28077620-c9f6-11eb-8785-acde48001122 version: 2 -date: '2022-03-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -31,12 +31,13 @@ references: - https://www.splunk.com/en_us/blog/security/hunting-for-malicious-powershell-using-script-block-logging.html tags: analytic_story: - - Hermetic Wiper - - Ransomware - - Malicious PowerShell - Qakbot - Windows Post-Exploitation + - Hermetic Wiper + - Ransomware - Prestige Ransomware + - Malicious PowerShell + - Data Destruction asset_type: Endpoint confidence: 80 impact: 70 diff --git a/detections/endpoint/recon_using_wmi_class.yml b/detections/endpoint/recon_using_wmi_class.yml index 2c944dc7cc..27501846af 100644 --- a/detections/endpoint/recon_using_wmi_class.yml +++ b/detections/endpoint/recon_using_wmi_class.yml @@ -1,7 +1,7 @@ name: Recon Using WMI Class id: 018c1972-ca07-11eb-9473-acde48001122 version: 2 -date: '2022-10-10' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -36,12 +36,13 @@ references: - https://blogs.vmware.com/security/2022/10/lockbit-3-0-also-known-as-lockbit-black.html tags: analytic_story: - - Hermetic Wiper - - Malicious PowerShell - - Industroyer2 - - Qakbot - - LockBit Ransomware - AsyncRAT + - Qakbot + - Industroyer2 + - Hermetic Wiper + - LockBit Ransomware + - Malicious PowerShell + - Data Destruction asset_type: Endpoint confidence: 80 impact: 75 diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index 9e67722f0b..93402a1713 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -1,7 +1,7 @@ name: Registry Keys Used For Privilege Escalation id: c9f4b923-f8af-4155-b697-1354f5bcbc5e version: 6 -date: '2022-11-14' +date: '2023-04-14' author: Steven Dick, David Dorsey, Teoderick Contreras, Splunk status: production type: TTP @@ -34,11 +34,12 @@ references: - https://blog.malwarebytes.com/101/2015/12/an-introduction-to-image-file-execution-options/ tags: analytic_story: - - Windows Privilege Escalation - - Suspicious Windows Registry Activities - Cloud Federated Credential Abuse - - Windows Registry Abuse - Hermetic Wiper + - Windows Privilege Escalation + - Windows Registry Abuse + - Data Destruction + - Suspicious Windows Registry Activities asset_type: Endpoint confidence: 95 impact: 80 diff --git a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml index feb86aeefe..0ffd192375 100644 --- a/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml +++ b/detections/endpoint/regsvr32_silent_and_install_param_dll_loading.yml @@ -1,7 +1,7 @@ name: Regsvr32 Silent and Install Param Dll Loading id: f421c250-24e7-11ec-bc43-acde48001122 version: 1 -date: '2021-10-04' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -31,12 +31,12 @@ references: - https://attack.mitre.org/techniques/T1218/010/ tags: analytic_story: - - Data Destruction - - Suspicious Regsvr32 Activity - - Remcos + - AsyncRAT - Hermetic Wiper - Living Off The Land - - AsyncRAT + - Data Destruction + - Remcos + - Suspicious Regsvr32 Activity asset_type: Endpoint confidence: 60 impact: 60 diff --git a/detections/endpoint/runas_execution_in_commandline.yml b/detections/endpoint/runas_execution_in_commandline.yml index 50b9e3bdee..f2f91a88bc 100644 --- a/detections/endpoint/runas_execution_in_commandline.yml +++ b/detections/endpoint/runas_execution_in_commandline.yml @@ -1,7 +1,7 @@ name: Runas Execution in CommandLine id: 4807e716-43a4-11ec-a0e7-acde48001122 version: 1 -date: '2021-11-12' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Hunting @@ -31,8 +31,9 @@ references: - https://app.any.run/tasks/ad4c3cda-41f2-4401-8dba-56cc2d245488/ tags: analytic_story: - - Windows Privilege Escalation + - Data Destruction - Hermetic Wiper + - Windows Privilege Escalation asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/schtasks_run_task_on_demand.yml b/detections/endpoint/schtasks_run_task_on_demand.yml index 3be0d77b3e..e37c88482a 100644 --- a/detections/endpoint/schtasks_run_task_on_demand.yml +++ b/detections/endpoint/schtasks_run_task_on_demand.yml @@ -1,7 +1,7 @@ name: Schtasks Run Task On Demand id: bb37061e-af1f-11eb-a159-acde48001122 version: 1 -date: '2021-05-07' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -27,10 +27,11 @@ references: - https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/ tags: analytic_story: - - XMRig - - Industroyer2 - - CISA AA22-257A - Qakbot + - Industroyer2 + - XMRig + - CISA AA22-257A + - Data Destruction asset_type: Endpoint confidence: 80 impact: 60 diff --git a/detections/endpoint/screensaver_event_trigger_execution.yml b/detections/endpoint/screensaver_event_trigger_execution.yml index 64a26c6c42..d09c9a532b 100644 --- a/detections/endpoint/screensaver_event_trigger_execution.yml +++ b/detections/endpoint/screensaver_event_trigger_execution.yml @@ -1,7 +1,7 @@ name: Screensaver Event Trigger Execution id: 58cea3ec-1f6d-11ec-8560-acde48001122 version: 1 -date: '2021-09-27' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -30,10 +30,11 @@ references: - https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver tags: analytic_story: - - Windows Persistence Techniques - - Windows Privilege Escalation - - Windows Registry Abuse - Hermetic Wiper + - Windows Privilege Escalation + - Windows Persistence Techniques + - Windows Registry Abuse + - Data Destruction asset_type: Endpoint confidence: 90 impact: 80 diff --git a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index dac2bdbee2..a345fceaea 100644 --- a/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -1,7 +1,7 @@ name: Set Default PowerShell Execution Policy To Unrestricted or Bypass id: c2590137-0b08-4985-9ec5-6ae23d92f63d version: 8 -date: '2022-11-14' +date: '2023-04-14' author: Steven Dick, Patrick Bareiss, Splunk status: production type: TTP @@ -33,10 +33,11 @@ known_false_positives: Administrators may attempt to change the default executio references: [] tags: analytic_story: - - Hermetic Wiper - - Malicious PowerShell - - Credential Dumping - HAFNIUM Group + - Hermetic Wiper + - Credential Dumping + - Malicious PowerShell + - Data Destruction asset_type: Endpoint confidence: 80 impact: 60 diff --git a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml index 5a714ed549..22bea94be5 100644 --- a/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml +++ b/detections/endpoint/suspicious_process_dns_query_known_abuse_web_services.yml @@ -1,7 +1,7 @@ name: Suspicious Process DNS Query Known Abuse Web Services id: 3cf0dc36-484d-11ec-a6bc-acde48001122 version: 2 -date: '2022-01-18' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -29,8 +29,9 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Remcos + - Data Destruction - WhisperGate + - Remcos asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/suspicious_process_file_path.yml b/detections/endpoint/suspicious_process_file_path.yml index 555d665b53..2c4a9f0289 100644 --- a/detections/endpoint/suspicious_process_file_path.yml +++ b/detections/endpoint/suspicious_process_file_path.yml @@ -1,7 +1,7 @@ name: Suspicious Process File Path id: 9be25988-ad82-11eb-a14f-acde48001122 version: 1 -date: '2023-01-25' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -35,25 +35,25 @@ references: - https://malpedia.caad.fkie.fraunhofer.de/details/win.asyncrat tags: analytic_story: - - Data Destruction - - Double Zero Destructor - - XMRig - - Remcos - - WhisperGate - - Hermetic Wiper - - Industroyer2 - - DarkCrystal RAT - - Brute Ratel C4 - AgentTesla + - Swift Slicer + - Prestige Ransomware + - Data Destruction + - AsyncRAT + - Brute Ratel C4 + - XMRig + - LockBit Ransomware + - WhisperGate + - DarkCrystal RAT - Qakbot + - Hermetic Wiper + - Chaos Ransomware + - Azorult + - Double Zero Destructor + - Industroyer2 - IcedID - Trickbot - - Azorult - - Prestige Ransomware - - Chaos Ransomware - - LockBit Ransomware - - AsyncRAT - - Swift Slicer + - Remcos asset_type: Endpoint confidence: 50 impact: 70 diff --git a/detections/endpoint/suspicious_process_with_discord_dns_query.yml b/detections/endpoint/suspicious_process_with_discord_dns_query.yml index ccf6ca7c26..8d88afd54f 100644 --- a/detections/endpoint/suspicious_process_with_discord_dns_query.yml +++ b/detections/endpoint/suspicious_process_with_discord_dns_query.yml @@ -1,7 +1,7 @@ name: Suspicious Process With Discord DNS Query id: 4d4332ae-792c-11ec-89c1-acde48001122 version: 2 -date: '2022-06-01' +date: '2023-04-14' author: Teoderick Contreras, Mauricio Velazco, Splunk status: production type: Anomaly @@ -27,6 +27,7 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: + - Data Destruction - WhisperGate asset_type: Endpoint confidence: 80 diff --git a/detections/endpoint/time_provider_persistence_registry.yml b/detections/endpoint/time_provider_persistence_registry.yml index d1f7ae0a7d..1250cb8987 100644 --- a/detections/endpoint/time_provider_persistence_registry.yml +++ b/detections/endpoint/time_provider_persistence_registry.yml @@ -1,7 +1,7 @@ name: Time Provider Persistence Registry id: 5ba382c4-2105-11ec-8d8f-acde48001122 version: 3 -date: '2022-11-14' +date: '2023-04-14' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -34,10 +34,11 @@ references: - https://attack.mitre.org/techniques/T1547/003/ tags: analytic_story: - - Windows Persistence Techniques - - Windows Privilege Escalation - - Windows Registry Abuse - Hermetic Wiper + - Windows Privilege Escalation + - Windows Persistence Techniques + - Windows Registry Abuse + - Data Destruction asset_type: Endpoint confidence: 100 impact: 80 diff --git a/detections/endpoint/unloading_amsi_via_reflection.yml b/detections/endpoint/unloading_amsi_via_reflection.yml index 040ea06e74..36a6354010 100644 --- a/detections/endpoint/unloading_amsi_via_reflection.yml +++ b/detections/endpoint/unloading_amsi_via_reflection.yml @@ -1,7 +1,7 @@ name: Unloading AMSI via Reflection id: a21e3484-c94d-11eb-b55b-acde48001122 version: 1 -date: '2021-06-09' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -37,8 +37,9 @@ references: - https://www.crowdstrike.com/blog/investigating-powershell-command-and-script-logging/ tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/w3wp_spawning_shell.yml b/detections/endpoint/w3wp_spawning_shell.yml index 442d168b02..76d21f86e5 100644 --- a/detections/endpoint/w3wp_spawning_shell.yml +++ b/detections/endpoint/w3wp_spawning_shell.yml @@ -1,7 +1,7 @@ name: W3WP Spawning Shell id: 0f03423c-7c6a-11eb-bc47-acde48001122 version: 2 -date: '2021-03-03' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -36,12 +36,13 @@ references: - https://www.huntress.com/blog/rapid-response-microsoft-exchange-servers-still-vulnerable-to-proxyshell-exploit#what-should-you-do tags: analytic_story: - - Hermetic Wiper - HAFNIUM Group + - CISA AA22-264A + - Hermetic Wiper + - ProxyNotShell - ProxyShell - CISA AA22-257A - - ProxyNotShell - - CISA AA22-264A + - Data Destruction asset_type: Endpoint confidence: 80 cve: diff --git a/detections/endpoint/windows_data_destruction_recursive_exec_files_deletion.yml b/detections/endpoint/windows_data_destruction_recursive_exec_files_deletion.yml index 3ba4e28c52..f5b25908e0 100644 --- a/detections/endpoint/windows_data_destruction_recursive_exec_files_deletion.yml +++ b/detections/endpoint/windows_data_destruction_recursive_exec_files_deletion.yml @@ -1,7 +1,7 @@ name: Windows Data Destruction Recursive Exec Files Deletion id: 3596a799-6320-4a2f-8772-a9e98ddb2960 version: 1 -date: '2023-02-02' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -30,6 +30,7 @@ references: tags: analytic_story: - Swift Slicer + - Data Destruction asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path.yml b/detections/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path.yml index 63ce4c6f71..c5c4616269 100644 --- a/detections/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path.yml +++ b/detections/endpoint/windows_deleted_registry_by_a_non_critical_process_file_path.yml @@ -1,7 +1,7 @@ name: Windows Deleted Registry By A Non Critical Process File Path id: 15e70689-f55b-489e-8a80-6d0cd6d8aad2 version: 2 -date: '2022-11-14' +date: '2023-04-14' author: Steven Dick, Teoderick Contreras, Splunk status: production type: Anomaly @@ -35,6 +35,7 @@ references: - https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html tags: analytic_story: + - Data Destruction - Double Zero Destructor asset_type: Endpoint confidence: 60 diff --git a/detections/endpoint/windows_disable_memory_crash_dump.yml b/detections/endpoint/windows_disable_memory_crash_dump.yml index e230023818..4167f9f3a2 100644 --- a/detections/endpoint/windows_disable_memory_crash_dump.yml +++ b/detections/endpoint/windows_disable_memory_crash_dump.yml @@ -1,7 +1,7 @@ name: Windows Disable Memory Crash Dump id: 59e54602-9680-11ec-a8a6-acde48001122 version: 1 -date: '2022-02-25' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -36,10 +36,10 @@ references: - https://docs.microsoft.com/en-us/troubleshoot/windows-server/performance/memory-dump-file-options tags: analytic_story: - - Data Destruction - Ransomware - - Hermetic Wiper + - Data Destruction - Windows Registry Abuse + - Hermetic Wiper asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml index fe9103d5e6..0378b37200 100644 --- a/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml +++ b/detections/endpoint/windows_dotnet_binary_in_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows DotNet Binary in Non Standard Path id: fddf3b56-7933-11ec-98a6-acde48001122 version: 1 -date: '2022-01-19' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -39,9 +39,10 @@ references: tags: analytic_story: - Masquerading - Rename System Utilities - - Unusual Processes - Ransomware + - Unusual Processes - Signed Binary Proxy Execution InstallUtil + - Data Destruction - WhisperGate asset_type: Endpoint confidence: 70 diff --git a/detections/endpoint/windows_file_without_extension_in_critical_folder.yml b/detections/endpoint/windows_file_without_extension_in_critical_folder.yml index 4bd54c94a9..926df20a80 100644 --- a/detections/endpoint/windows_file_without_extension_in_critical_folder.yml +++ b/detections/endpoint/windows_file_without_extension_in_critical_folder.yml @@ -1,7 +1,7 @@ name: Windows File Without Extension In Critical Folder id: 0dbcac64-963c-11ec-bf04-acde48001122 version: 1 -date: '2022-02-25' +date: '2023-04-14' author: Teoderick Contreras, Bhavin Patel, Splunk status: production type: TTP diff --git a/detections/endpoint/windows_hidden_schedule_task_settings.yml b/detections/endpoint/windows_hidden_schedule_task_settings.yml index fbfc718a57..cda87bdaaa 100644 --- a/detections/endpoint/windows_hidden_schedule_task_settings.yml +++ b/detections/endpoint/windows_hidden_schedule_task_settings.yml @@ -1,7 +1,7 @@ name: Windows Hidden Schedule Task Settings id: 0b730470-5fe8-4b13-93a7-fe0ad014d0cc version: 1 -date: '2022-04-26' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -25,9 +25,10 @@ references: - https://cert.gov.ua/article/39518 tags: analytic_story: - - Industroyer2 - - Active Directory Discovery - CISA AA22-257A + - Active Directory Discovery + - Industroyer2 + - Data Destruction asset_type: Endpoint confidence: 80 impact: 80 diff --git a/detections/endpoint/windows_high_file_deletion_frequency.yml b/detections/endpoint/windows_high_file_deletion_frequency.yml index ba2ed7f49f..47e6e0d8a7 100644 --- a/detections/endpoint/windows_high_file_deletion_frequency.yml +++ b/detections/endpoint/windows_high_file_deletion_frequency.yml @@ -1,7 +1,7 @@ name: Windows High File Deletion Frequency id: 45b125c4-866f-11eb-a95a-acde48001122 version: 1 -date: '2021-03-16' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -29,9 +29,10 @@ references: tags: analytic_story: - Clop Ransomware - - WhisperGate - DarkCrystal RAT - Swift Slicer + - Data Destruction + - WhisperGate asset_type: Endpoint confidence: 80 impact: 90 diff --git a/detections/endpoint/windows_installutil_in_non_standard_path.yml b/detections/endpoint/windows_installutil_in_non_standard_path.yml index 0f1aeda0a2..a87f4d7666 100644 --- a/detections/endpoint/windows_installutil_in_non_standard_path.yml +++ b/detections/endpoint/windows_installutil_in_non_standard_path.yml @@ -1,7 +1,7 @@ name: Windows InstallUtil in Non Standard Path id: dcf74b22-7933-11ec-857c-acde48001122 version: 1 -date: '2022-01-19' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -34,11 +34,12 @@ references: tags: analytic_story: - Masquerading - Rename System Utilities - - Unusual Processes - Ransomware + - Unusual Processes - Signed Binary Proxy Execution InstallUtil - - WhisperGate - Living Off The Land + - Data Destruction + - WhisperGate asset_type: Endpoint confidence: 70 impact: 70 diff --git a/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml b/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml index f35c1e30a8..e954bb5b34 100644 --- a/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml +++ b/detections/endpoint/windows_linked_policies_in_adsi_discovery.yml @@ -1,7 +1,7 @@ name: Windows Linked Policies In ADSI Discovery id: 510ea428-4731-4d2f-8829-a28293e427aa version: 1 -date: '2022-04-25' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -25,8 +25,9 @@ references: - https://medium.com/@pentesttas/discover-hidden-gpo-s-on-active-directory-using-ps-adsi-a284b6814c81 tags: analytic_story: - - Industroyer2 + - Data Destruction - Active Directory Discovery + - Industroyer2 asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/windows_modify_show_compress_color_and_info_tip_registry.yml b/detections/endpoint/windows_modify_show_compress_color_and_info_tip_registry.yml index 9eeed3b765..a7ffd67283 100644 --- a/detections/endpoint/windows_modify_show_compress_color_and_info_tip_registry.yml +++ b/detections/endpoint/windows_modify_show_compress_color_and_info_tip_registry.yml @@ -1,7 +1,7 @@ name: Windows Modify Show Compress Color And Info Tip Registry id: b7548c2e-9a10-11ec-99e3-acde48001122 version: 2 -date: '2022-11-14' +date: '2023-04-14' author: Steven Dick, Teoderick Contreras, Splunk status: production type: TTP @@ -37,8 +37,8 @@ tags: analytic_story: - Data Destruction - Windows Defense Evasion Tactics - - Hermetic Wiper - Windows Registry Abuse + - Hermetic Wiper asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/windows_nirsoft_advancedrun.yml b/detections/endpoint/windows_nirsoft_advancedrun.yml index 5d1d82cd76..db3bdab6c5 100644 --- a/detections/endpoint/windows_nirsoft_advancedrun.yml +++ b/detections/endpoint/windows_nirsoft_advancedrun.yml @@ -1,7 +1,7 @@ name: Windows NirSoft AdvancedRun id: bb4f3090-7ae4-11ec-897f-acde48001122 version: 1 -date: '2022-01-21' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: TTP @@ -31,8 +31,9 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Unusual Processes - Ransomware + - Unusual Processes + - Data Destruction - WhisperGate asset_type: Endpoint confidence: 100 diff --git a/detections/endpoint/windows_nirsoft_utilities.yml b/detections/endpoint/windows_nirsoft_utilities.yml index b59cf7ec1f..00a0074fb9 100644 --- a/detections/endpoint/windows_nirsoft_utilities.yml +++ b/detections/endpoint/windows_nirsoft_utilities.yml @@ -1,7 +1,7 @@ name: Windows NirSoft Utilities id: 5b2f4596-7d4c-11ec-88a7-acde48001122 version: 1 -date: '2022-01-24' +date: '2023-04-14' author: Michael Haag, Splunk status: production type: Hunting @@ -29,6 +29,7 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: + - Data Destruction - WhisperGate asset_type: Endpoint confidence: 100 diff --git a/detections/endpoint/windows_processes_killed_by_industroyer2_malware.yml b/detections/endpoint/windows_processes_killed_by_industroyer2_malware.yml index a39000c7e1..9741943019 100644 --- a/detections/endpoint/windows_processes_killed_by_industroyer2_malware.yml +++ b/detections/endpoint/windows_processes_killed_by_industroyer2_malware.yml @@ -1,7 +1,7 @@ name: Windows Processes Killed By Industroyer2 Malware id: d8bea5ca-9d4a-4249-8b56-64a619109835 version: 1 -date: '2022-04-22' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -26,6 +26,7 @@ references: - https://www.welivesecurity.com/2022/04/12/industroyer2-industroyer-reloaded/ tags: analytic_story: + - Data Destruction - Industroyer2 asset_type: Endpoint confidence: 60 diff --git a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml index 0cd7f6e06c..44ef4bf36e 100644 --- a/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml +++ b/detections/endpoint/windows_raw_access_to_disk_volume_partition.yml @@ -1,7 +1,7 @@ name: Windows Raw Access To Disk Volume Partition id: a85aa37e-9647-11ec-90c5-acde48001122 version: 1 -date: '2022-02-25' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -27,10 +27,10 @@ references: - https://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html tags: analytic_story: - - Caddy Wiper - - Data Destruction - - Hermetic Wiper - CISA AA22-264A + - Data Destruction + - Caddy Wiper + - Hermetic Wiper asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml index 7b4b1ef7e7..4ed481b408 100644 --- a/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml +++ b/detections/endpoint/windows_raw_access_to_master_boot_record_drive.yml @@ -1,7 +1,7 @@ name: Windows Raw Access To Master Boot Record Drive id: 7b83f666-900c-11ec-a2d9-acde48001122 version: 1 -date: '2022-02-17' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -29,11 +29,11 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - Data Destruction - Caddy Wiper - - WhisperGate - - Hermetic Wiper - CISA AA22-264A + - Hermetic Wiper + - Data Destruction + - WhisperGate asset_type: Endpoint confidence: 100 impact: 90 diff --git a/detections/endpoint/windows_root_domain_linked_policies_discovery.yml b/detections/endpoint/windows_root_domain_linked_policies_discovery.yml index 4ce41e050f..89cd8dfcdb 100644 --- a/detections/endpoint/windows_root_domain_linked_policies_discovery.yml +++ b/detections/endpoint/windows_root_domain_linked_policies_discovery.yml @@ -1,7 +1,7 @@ name: Windows Root Domain linked policies Discovery id: 80ffaede-1f12-49d5-a86e-b4b599b68b3c version: 1 -date: '2022-04-25' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -24,8 +24,9 @@ references: - https://medium.com/@pentesttas/discover-hidden-gpo-s-on-active-directory-using-ps-adsi-a284b6814c81 tags: analytic_story: - - Industroyer2 + - Data Destruction - Active Directory Discovery + - Industroyer2 asset_type: Endpoint confidence: 50 impact: 50 diff --git a/detections/endpoint/windows_terminating_lsass_process.yml b/detections/endpoint/windows_terminating_lsass_process.yml index 54b34c4ee0..e99c7b73d0 100644 --- a/detections/endpoint/windows_terminating_lsass_process.yml +++ b/detections/endpoint/windows_terminating_lsass_process.yml @@ -1,7 +1,7 @@ name: Windows Terminating Lsass Process id: 7ab3c319-a4e7-4211-9e8c-40a049d0dba6 version: 1 -date: '2022-03-28' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -33,6 +33,7 @@ references: - https://blog.talosintelligence.com/2022/03/threat-advisory-doublezero.html tags: analytic_story: + - Data Destruction - Double Zero Destructor asset_type: Endpoint confidence: 80 diff --git a/detections/endpoint/wmi_recon_running_process_or_services.yml b/detections/endpoint/wmi_recon_running_process_or_services.yml index aecb70f1dd..136d003ce8 100644 --- a/detections/endpoint/wmi_recon_running_process_or_services.yml +++ b/detections/endpoint/wmi_recon_running_process_or_services.yml @@ -1,7 +1,7 @@ name: WMI Recon Running Process Or Services id: b5cd5526-cce7-11eb-b3bd-acde48001122 version: 2 -date: '2022-05-02' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: Anomaly @@ -28,8 +28,9 @@ references: - https://in.security/2019/04/03/an-intro-into-abusing-and-identifying-wmi-event-subscriptions-for-persistence/ tags: analytic_story: - - Hermetic Wiper - Malicious PowerShell + - Hermetic Wiper + - Data Destruction asset_type: Endpoint confidence: 100 impact: 20 diff --git a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml index 1ee23e44c5..dab7c518b8 100644 --- a/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml +++ b/detections/endpoint/wscript_or_cscript_suspicious_child_process.yml @@ -1,7 +1,7 @@ name: Wscript Or Cscript Suspicious Child Process id: 1f35e1da-267b-11ec-90a9-acde48001122 version: 1 -date: '2021-10-06' +date: '2023-04-14' author: Teoderick Contreras, Splunk status: production type: TTP @@ -31,9 +31,10 @@ references: - https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/ tags: analytic_story: - - FIN7 - Remcos + - FIN7 - Unusual Processes + - Data Destruction - WhisperGate asset_type: Endpoint confidence: 70 diff --git a/stories/data_destruction.yml b/stories/data_destruction.yml index 45cd0ac30d..63e6ce508e 100644 --- a/stories/data_destruction.yml +++ b/stories/data_destruction.yml @@ -1,16 +1,29 @@ name: Data Destruction id: 4ae5c0d1-cebd-47d1-bfce-71bf096e38aa version: 1 -date: '2022-02-14' +date: '2023-04-06' author: Teoderick Contreras, Splunk -description: Leverage searches that allow you to detect and investigate unusual activities - that might relate to the data destruction, including deleting files, overwriting files, wiping disk and encrypting files. -narrative: Adversaries may use this technique to maximize the impact on the target organization in operations where network wide availability interruption - is the goal. +description: Leverage searches that allow you to detect and investigate unusual activities that might relate to the data destruction, + including deleting files, overwriting files, wiping disk and unrecoverable file encryption. This analytic story may cover several + known activities related to malware implants used in geo-political war to wipe disks or files to interrupt the network-wide operation + of a targeted organization. Analytics can detect the behavior of "DoubleZero Destructor", "CaddyWiper", "AcidRain", "AwfulShred", + "Hermetic Wiper", "Swift Slicer", "Whisper Gate" and many more. +narrative: Adversaries may partially or completely overwrite the contents of a storage device rendering the data irrecoverable through + the storage interface or using 3rd party drivers to directly access disk content like Master Boot Record to wipe it. + Some of these attacks were seen in geo-political war to impair the operation of targeted organizations or to interrupt network-wide services. references: - https://attack.mitre.org/techniques/T1485/ - https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/ - https://www.picussecurity.com/blog/a-brief-history-and-further-technical-analysis-of-sodinokibi-ransomware +- https://www.splunk.com/en_us/blog/security/threat-advisory-strt-ta02-destructive-software.html +- https://www.splunk.com/en_us/blog/security/detecting-hermeticwiper.html +- https://www.splunk.com/en_us/blog/security/threat-update-doublezero-destructor.html +- https://www.splunk.com/en_us/blog/security/threat-update-caddywiper.html +- https://www.splunk.com/en_us/blog/security/strt-ta03-cpe-destructive-software.html +- https://www.splunk.com/en_us/blog/security/threat-update-cyclopsblink.html +- https://www.splunk.com/en_us/blog/security/threat-update-acidrain-wiper.html +- https://www.splunk.com/en_us/blog/security/threat-update-industroyer2.html +- https://www.splunk.com/en_us/blog/security/threat-advisory-swiftslicer-wiper-strt-ta03.html tags: analytic_story: Data Destruction category: