mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -33,6 +33,7 @@ tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- NOBELIUM Group
|
||||
- Insider Threat
|
||||
cis20: []
|
||||
confidence: 60
|
||||
context:
|
||||
|
||||
@@ -32,6 +32,7 @@ tags:
|
||||
analytic_story:
|
||||
- Ryuk Ransomware
|
||||
- Ransomware
|
||||
- Information Sabotage
|
||||
cis20:
|
||||
- CIS 8
|
||||
confidence: 80
|
||||
|
||||
@@ -33,6 +33,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- XMRig
|
||||
- Information Sabotage
|
||||
cis20:
|
||||
- CIS 14
|
||||
- CIS 16
|
||||
|
||||
@@ -44,6 +44,7 @@ tags:
|
||||
analytic_story:
|
||||
- DarkSide Ransomware
|
||||
- Ransomware
|
||||
- Insider Threat
|
||||
cis20: []
|
||||
confidence: 70
|
||||
context:
|
||||
|
||||
@@ -33,6 +33,8 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
- Insider Threat
|
||||
- Information Sabotage
|
||||
cis20: []
|
||||
confidence: 90
|
||||
context:
|
||||
|
||||
@@ -33,6 +33,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- XMRig
|
||||
- Insider Threat
|
||||
cis20:
|
||||
- CIS 14
|
||||
- CIS 16
|
||||
|
||||
@@ -36,6 +36,7 @@ tags:
|
||||
- Windows Defense Evasion Tactics
|
||||
- Windows Persistence Techniques
|
||||
- Information Sabotage
|
||||
- Insider Threat
|
||||
cis20:
|
||||
- CIS 14
|
||||
- CIS 16
|
||||
|
||||
@@ -38,6 +38,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Command-Line Executions
|
||||
- Insider Threat
|
||||
cis20:
|
||||
- CIS 8
|
||||
confidence: 50
|
||||
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Windows Log Manipulation
|
||||
- Ransomware
|
||||
- Clop Ransomware
|
||||
- Insider Threat
|
||||
cis20:
|
||||
- CIS 8
|
||||
- CIS 13
|
||||
|
||||
@@ -34,6 +34,8 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Log Manipulation
|
||||
- Ransomware
|
||||
- Insider Threat
|
||||
- Information Sabotage
|
||||
cis20:
|
||||
- CIS 8
|
||||
- CIS 13
|
||||
|
||||
@@ -52,6 +52,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ingress Tool Transfer
|
||||
- Insider Threat
|
||||
cis20: []
|
||||
confidence: 100
|
||||
context:
|
||||
|
||||
@@ -28,6 +28,7 @@ tags:
|
||||
analytic_story:
|
||||
- Cobalt Strike
|
||||
- NOBELIUM Group
|
||||
- Insider Threat
|
||||
cis20: []
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
|
||||
@@ -27,6 +27,7 @@ tags:
|
||||
analytic_story:
|
||||
- Ryuk Ransomware
|
||||
- Ransomware
|
||||
- Information Sabotage
|
||||
cis20:
|
||||
- CIS 8
|
||||
kill_chain_phases:
|
||||
|
||||
@@ -28,6 +28,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- XMRig
|
||||
- Information Sabotage
|
||||
cis20:
|
||||
- CIS 14
|
||||
- CIS 16
|
||||
|
||||
@@ -33,6 +33,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Suspicious Command-Line Executions
|
||||
- Insider Threat
|
||||
cis20:
|
||||
- CIS 8
|
||||
kill_chain_phases:
|
||||
|
||||
@@ -39,6 +39,7 @@ tags:
|
||||
analytic_story:
|
||||
- DarkSide Ransomware
|
||||
- Ransomware
|
||||
- Insider Threat
|
||||
cis20: []
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
|
||||
+2
@@ -28,6 +28,8 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ransomware
|
||||
- Insider Threat
|
||||
- Information Sabotage
|
||||
cis20: []
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
|
||||
@@ -28,6 +28,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- XMRig
|
||||
- Insider Threat
|
||||
cis20:
|
||||
- CIS 14
|
||||
- CIS 16
|
||||
|
||||
@@ -31,6 +31,7 @@ tags:
|
||||
- Windows Defense Evasion Tactics
|
||||
- Windows Persistence Techniques
|
||||
- Information Sabotage
|
||||
- Insider Threat
|
||||
cis20:
|
||||
- CIS 14
|
||||
- CIS 16
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
- Windows Log Manipulation
|
||||
- Ransomware
|
||||
- Clop Ransomware
|
||||
- Insider Threat
|
||||
cis20:
|
||||
- CIS 8
|
||||
- CIS 13
|
||||
|
||||
@@ -29,6 +29,8 @@ tags:
|
||||
analytic_story:
|
||||
- Windows Log Manipulation
|
||||
- Ransomware
|
||||
- Insider Threat
|
||||
- Information Sabotage
|
||||
cis20:
|
||||
- CIS 8
|
||||
- CIS 13
|
||||
|
||||
@@ -47,6 +47,7 @@ references:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Ingress Tool Transfer
|
||||
- Insider Threat
|
||||
cis20: []
|
||||
kill_chain_phases:
|
||||
- Exploitation
|
||||
|
||||
Reference in New Issue
Block a user