Branch was auto-updated.

This commit is contained in:
github-actions[bot]
2021-08-16 19:02:25 +00:00
committed by GitHub
47 changed files with 1030 additions and 0 deletions
@@ -59,3 +59,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is violating authentication processes by injecting golden or silver Kerberos tickets or passing stolen authentication tokens. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -63,3 +63,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is violating authentication by injecting stolen credentials, manipulating authentication tokens or impersonating system or user accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -51,3 +51,25 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: DSInternals tool kit is assessing password strength at the device $dest_device_id$. Account attempting this operation is $dest_user_id$ via command $cmd_line$
risk_score: 25
impact: 30
confidence: 85
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -50,3 +50,24 @@ tags:
- process
risk_severity: low
security_domain: endpoint
message: Malicious actor is dumping stored credentials from the registry sections SAM, Security, or System. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 63
impact: 70
confidence: 90
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -62,3 +62,24 @@ tags:
- process
risk_severity: high
security_domain: endpoint
message: DSInternals tool kit is converting stolen credential material to a form applicable to authentications. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -63,3 +63,24 @@ tags:
- process
risk_severity: high
security_domain: endpoint
message: DSInternals tool kit is accessing sensitive credential material such as KDS root key, or accessing sensitive authentication infrastructure such as LsaPolicyInformation. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -59,3 +59,25 @@ tags:
- process
risk_severity: high
security_domain: endpoint
message: Malicious actor is accessing stored credentials via FGDump or CacheDump tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -56,3 +56,24 @@ tags:
- process
risk_severity: high
security_domain: endpoint
message: Malicious actor is accessing stored credentials via FGDump or CacheDump tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 63
impact: 70
confidence: 90
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -51,3 +51,24 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is accessing stored credentials via Get-ADDBAccount module. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 63
impact: 70
confidence: 90
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -50,3 +50,24 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: Lazagne malware is extracting/decoding encoded credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 63
impact: 70
confidence: 90
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -55,3 +55,24 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is extracting/decoding encoded credentials from stores such as SAM or LSA dumps. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 66
impact: 70
confidence: 95
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -60,3 +60,24 @@ tags:
- process
risk_severity: medium
security_domain: endpoint
message: Malicious actor is extracting/decoding encoded credentials via Microsoft's native debugging tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 63
impact: 70
confidence: 90
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -56,3 +56,24 @@ tags:
- process
risk_severity: medium
security_domain: endpoint
message: Malicious actor is extracting/decoding encoded credentials via Microsoft's native debugging tools. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 63
impact: 70
confidence: 90
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -56,3 +56,24 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is extracting encoded credentials or spoofing automated logings. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -46,3 +46,24 @@ tags:
- process
risk_severity: low
security_domain: endpoint
message: Malicious actor is dumping encoded credentials via Microsoft's native comsvc DLL. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -51,3 +51,24 @@ tags:
- ticket_options
risk_severity: low
security_domain: endpoint
message: Kerberoasting malware is potentially applying stolen credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 14
impact: 70
confidence: 20
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -56,3 +56,24 @@ tags:
- dest_device_id
risk_severity: low
security_domain: endpoint
message: Potential use of the pass the hash/token attacks that spoof authentication. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 16
impact: 80
confidence: 20
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -55,3 +55,27 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is tapping into user content - microphone, camera, ongoing HTTP or RDP session. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 85
impact: 85
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Exfiltration
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -48,3 +48,26 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is creating illegal domain accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Persistence
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -50,3 +50,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: DSInternals malware is illegally enabling or disabling accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -48,3 +48,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is deleting event logs to cover tracks of malicious activity. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 50
impact: 50
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -53,3 +53,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: DSInternals malware is controlling infrastructure by modifying Active Directory elements, domain controllers, and policies. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -54,3 +54,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is controlling infrastructure by modifying Active Directory elements or local Master Boot Records. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -54,3 +54,27 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is planting attack persistence elements, altering privileges and access controls. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Command And Control
- Stage:Persistence
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -50,3 +50,26 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is setting highest privileges to malicious entities. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Privilege Escalation
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -53,3 +53,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is controlling computer's processess and services. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -63,3 +63,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is controlling computer's processess and services. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -48,3 +48,25 @@ tags:
- dest_device_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is probing access with stolen credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 60
impact: 60
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -58,3 +58,25 @@ tags:
- dest_user_id
risk_severity: low
security_domain: endpoint
message: Potential malicious landing to the console via unexpected programs that called cmd.exe. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ where parent process $parent_process$ spwaned $process_name$.
risk_score: 56
impact: 70
confidence: 80
context:
- Source:AD
- Source:Endpoint
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -64,3 +64,24 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is searching for an entry point into the infrastructure, such as local admin accounts, opportunities to hijack processes, unattended install files, or modifiable access objects. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 60
impact: 60
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -70,3 +70,26 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is searching for and using specific accounts, groups and policies, such as the last logged on account, a local Net group, etc. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -48,3 +48,26 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is searching for and using specific accounts and groups. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -61,3 +61,26 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is seaching for or accessing Active Directory objects such as domain sites, domain trusts, AD forests, etc. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -53,3 +53,26 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is seaching for or accessing domain controllers, computers, file servers, etc. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -46,3 +46,24 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is collecting information about computers. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 50
impact: 50
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -60,3 +60,26 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is searching for and tapping into ongoing processes, mounted drives or other operating system elements. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -48,3 +48,26 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is searching for and accessing network shares. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Lateral Movement
- Stage:Collection
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -52,3 +52,26 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is searching for and accessing network shares. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Lateral Movement
- Stage:Collection
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -54,3 +54,24 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is performing port scans or searching for various connectivity details such as DNS data, proxies, or ongoing RDP connections. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -53,3 +53,25 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is searching for and accessing credential stores. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Credential Access
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -47,3 +47,24 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is looking for presence of anti virus software. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 40
impact: 40
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -48,3 +48,24 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is engaging its privilege escalation module. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 60
impact: 60
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -53,3 +53,26 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is looking for and invoking Microsoft Detours package that enables spoofing of in-memory code. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 70
impact: 70
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
- Stage:Command And Control
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -48,3 +48,24 @@ tags:
- dest_user_id
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is listing processes and services. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 50
impact: 50
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Recon
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -59,3 +59,26 @@ tags:
- process
risk_severity: high
security_domain: endpoint
message: DSInternals malware is accessing, using or setting Active Directory or Azure credentials and accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Source:Cloud Data
- Stage:Credential Access
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -50,3 +50,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: Mimikatz malware is accessing, using or setting account credentials. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 80
impact: 80
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others
@@ -50,3 +50,25 @@ tags:
- _time
risk_severity: high
security_domain: endpoint
message: PowerSploit malware is setting passwords on Active Directory accounts. Operation is performed at the device $dest_device_id$, by the account $dest_user_id$ via command $cmd_line$
risk_score: 90
impact: 90
confidence: 100
context:
- Source:AD
- Source:Endpoint
- Stage:Credential Access
- Consequence:Loss Of Control
observable:
- name: dest_user_id
type: User
role:
- Actor
- name: dest_device_id
type: Hostname
role:
- Victim
- name: cmd_line
type: processname
role:
- Others