Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-09-14 09:38:22 -07:00
committed by GitHub
22 changed files with 26 additions and 0 deletions
@@ -33,6 +33,7 @@ tags:
analytic_story:
- Cobalt Strike
- NOBELIUM Group
- Insider Threat
cis20: []
confidence: 60
context:
@@ -32,6 +32,7 @@ tags:
analytic_story:
- Ryuk Ransomware
- Ransomware
- Information Sabotage
cis20:
- CIS 8
confidence: 80
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- XMRig
- Information Sabotage
cis20:
- CIS 14
- CIS 16
@@ -44,6 +44,7 @@ tags:
analytic_story:
- DarkSide Ransomware
- Ransomware
- Insider Threat
cis20: []
confidence: 70
context:
@@ -33,6 +33,8 @@ references:
tags:
analytic_story:
- Ransomware
- Insider Threat
- Information Sabotage
cis20: []
confidence: 90
context:
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- XMRig
- Insider Threat
cis20:
- CIS 14
- CIS 16
@@ -36,6 +36,7 @@ tags:
- Windows Defense Evasion Tactics
- Windows Persistence Techniques
- Information Sabotage
- Insider Threat
cis20:
- CIS 14
- CIS 16
@@ -38,6 +38,7 @@ references:
tags:
analytic_story:
- Suspicious Command-Line Executions
- Insider Threat
cis20:
- CIS 8
confidence: 50
@@ -38,6 +38,7 @@ tags:
- Windows Log Manipulation
- Ransomware
- Clop Ransomware
- Insider Threat
cis20:
- CIS 8
- CIS 13
@@ -34,6 +34,8 @@ tags:
analytic_story:
- Windows Log Manipulation
- Ransomware
- Insider Threat
- Information Sabotage
cis20:
- CIS 8
- CIS 13
@@ -52,6 +52,7 @@ references:
tags:
analytic_story:
- Ingress Tool Transfer
- Insider Threat
cis20: []
confidence: 100
context:
@@ -28,6 +28,7 @@ tags:
analytic_story:
- Cobalt Strike
- NOBELIUM Group
- Insider Threat
cis20: []
kill_chain_phases:
- Exploitation
@@ -27,6 +27,7 @@ tags:
analytic_story:
- Ryuk Ransomware
- Ransomware
- Information Sabotage
cis20:
- CIS 8
kill_chain_phases:
@@ -28,6 +28,7 @@ references:
tags:
analytic_story:
- XMRig
- Information Sabotage
cis20:
- CIS 14
- CIS 16
@@ -33,6 +33,7 @@ references:
tags:
analytic_story:
- Suspicious Command-Line Executions
- Insider Threat
cis20:
- CIS 8
kill_chain_phases:
@@ -39,6 +39,7 @@ tags:
analytic_story:
- DarkSide Ransomware
- Ransomware
- Insider Threat
cis20: []
kill_chain_phases:
- Exploitation
+2
View File
@@ -28,6 +28,8 @@ references:
tags:
analytic_story:
- Ransomware
- Insider Threat
- Information Sabotage
cis20: []
kill_chain_phases:
- Exploitation
@@ -28,6 +28,7 @@ references:
tags:
analytic_story:
- XMRig
- Insider Threat
cis20:
- CIS 14
- CIS 16
@@ -31,6 +31,7 @@ tags:
- Windows Defense Evasion Tactics
- Windows Persistence Techniques
- Information Sabotage
- Insider Threat
cis20:
- CIS 14
- CIS 16
+1
View File
@@ -33,6 +33,7 @@ tags:
- Windows Log Manipulation
- Ransomware
- Clop Ransomware
- Insider Threat
cis20:
- CIS 8
- CIS 13
+2
View File
@@ -29,6 +29,8 @@ tags:
analytic_story:
- Windows Log Manipulation
- Ransomware
- Insider Threat
- Information Sabotage
cis20:
- CIS 8
- CIS 13
@@ -47,6 +47,7 @@ references:
tags:
analytic_story:
- Ingress Tool Transfer
- Insider Threat
cis20: []
kill_chain_phases:
- Exploitation