diff --git a/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml b/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml index a2158e2e05..4bf28ca116 100644 --- a/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml +++ b/detections/endpoint/ssa___anomalous_usage_of_archive_tools.yml @@ -33,6 +33,7 @@ tags: analytic_story: - Cobalt Strike - NOBELIUM Group + - Insider Threat cis20: [] confidence: 60 context: diff --git a/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml b/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml index 144bc6c4a1..b75f777346 100644 --- a/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/ssa___bcdedit_failure_recovery_modification.yml @@ -32,6 +32,7 @@ tags: analytic_story: - Ryuk Ransomware - Ransomware + - Information Sabotage cis20: - CIS 8 confidence: 80 diff --git a/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml b/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml index f2ee2b55d6..6bd84ffc1e 100644 --- a/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml +++ b/detections/endpoint/ssa___deny_permission_using_cacls_utility.yml @@ -33,6 +33,7 @@ references: tags: analytic_story: - XMRig + - Information Sabotage cis20: - CIS 14 - CIS 16 diff --git a/detections/endpoint/ssa___detect_rclone_command_line_usage.yml b/detections/endpoint/ssa___detect_rclone_command_line_usage.yml index a1ba6e1c39..c3172bf972 100644 --- a/detections/endpoint/ssa___detect_rclone_command_line_usage.yml +++ b/detections/endpoint/ssa___detect_rclone_command_line_usage.yml @@ -44,6 +44,7 @@ tags: analytic_story: - DarkSide Ransomware - Ransomware + - Insider Threat cis20: [] confidence: 70 context: diff --git a/detections/endpoint/ssa___fsutil_zeroing_file.yml b/detections/endpoint/ssa___fsutil_zeroing_file.yml index de4c42036e..353f5c5a3d 100644 --- a/detections/endpoint/ssa___fsutil_zeroing_file.yml +++ b/detections/endpoint/ssa___fsutil_zeroing_file.yml @@ -33,6 +33,8 @@ references: tags: analytic_story: - Ransomware + - Insider Threat + - Information Sabotage cis20: [] confidence: 90 context: diff --git a/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml b/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml index 6a83005a02..59ef244d67 100644 --- a/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml +++ b/detections/endpoint/ssa___grant_permission_using_cacls_utility.yml @@ -33,6 +33,7 @@ references: tags: analytic_story: - XMRig + - Insider Threat cis20: - CIS 14 - CIS 16 diff --git a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml index 754b664337..fb925f5168 100644 --- a/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/ssa___hiding_files_and_directories_with_attrib_exe.yml @@ -36,6 +36,7 @@ tags: - Windows Defense Evasion Tactics - Windows Persistence Techniques - Information Sabotage + - Insider Threat cis20: - CIS 14 - CIS 16 diff --git a/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml b/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml index 9fcf4544f2..b2e285d4be 100644 --- a/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml +++ b/detections/endpoint/ssa___prohibited_apps_spawning_cmdprompt.yml @@ -38,6 +38,7 @@ references: tags: analytic_story: - Suspicious Command-Line Executions + - Insider Threat cis20: - CIS 8 confidence: 50 diff --git a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml index 6fb854e344..80c3811294 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_clear_logs.yml @@ -38,6 +38,7 @@ tags: - Windows Log Manipulation - Ransomware - Clop Ransomware + - Insider Threat cis20: - CIS 8 - CIS 13 diff --git a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml index 760a660a1a..6379f7dfff 100644 --- a/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml +++ b/detections/endpoint/ssa___wevtutil_usage_to_disable_logs.yml @@ -34,6 +34,8 @@ tags: analytic_story: - Windows Log Manipulation - Ransomware + - Insider Threat + - Information Sabotage cis20: - CIS 8 - CIS 13 diff --git a/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml b/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml index 569c72fe61..0741451060 100644 --- a/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml +++ b/detections/endpoint/ssa___windows_curl_upload_to_remote_destination.yml @@ -52,6 +52,7 @@ references: tags: analytic_story: - Ingress Tool Transfer + - Insider Threat cis20: [] confidence: 100 context: diff --git a/dist/ssa/srs/ssa___anomalous_usage_of_archive_tools.yml b/dist/ssa/srs/ssa___anomalous_usage_of_archive_tools.yml index 6569156817..ef21f81a22 100644 --- a/dist/ssa/srs/ssa___anomalous_usage_of_archive_tools.yml +++ b/dist/ssa/srs/ssa___anomalous_usage_of_archive_tools.yml @@ -28,6 +28,7 @@ tags: analytic_story: - Cobalt Strike - NOBELIUM Group + - Insider Threat cis20: [] kill_chain_phases: - Exploitation diff --git a/dist/ssa/srs/ssa___bcdedit_failure_recovery_modification.yml b/dist/ssa/srs/ssa___bcdedit_failure_recovery_modification.yml index a641bac103..2d5a4daffb 100644 --- a/dist/ssa/srs/ssa___bcdedit_failure_recovery_modification.yml +++ b/dist/ssa/srs/ssa___bcdedit_failure_recovery_modification.yml @@ -27,6 +27,7 @@ tags: analytic_story: - Ryuk Ransomware - Ransomware + - Information Sabotage cis20: - CIS 8 kill_chain_phases: diff --git a/dist/ssa/srs/ssa___deny_permission_using_cacls_utility.yml b/dist/ssa/srs/ssa___deny_permission_using_cacls_utility.yml index 4abed4382d..7b1b3db5de 100644 --- a/dist/ssa/srs/ssa___deny_permission_using_cacls_utility.yml +++ b/dist/ssa/srs/ssa___deny_permission_using_cacls_utility.yml @@ -28,6 +28,7 @@ references: tags: analytic_story: - XMRig + - Information Sabotage cis20: - CIS 14 - CIS 16 diff --git a/dist/ssa/srs/ssa___detect_prohibited_applications_spawning_cmd_exe.yml b/dist/ssa/srs/ssa___detect_prohibited_applications_spawning_cmd_exe.yml index 72227dde47..55ea07ea07 100644 --- a/dist/ssa/srs/ssa___detect_prohibited_applications_spawning_cmd_exe.yml +++ b/dist/ssa/srs/ssa___detect_prohibited_applications_spawning_cmd_exe.yml @@ -33,6 +33,7 @@ references: tags: analytic_story: - Suspicious Command-Line Executions + - Insider Threat cis20: - CIS 8 kill_chain_phases: diff --git a/dist/ssa/srs/ssa___detect_rclone_command_line_usage.yml b/dist/ssa/srs/ssa___detect_rclone_command_line_usage.yml index d5a54d0619..7baacb920d 100644 --- a/dist/ssa/srs/ssa___detect_rclone_command_line_usage.yml +++ b/dist/ssa/srs/ssa___detect_rclone_command_line_usage.yml @@ -39,6 +39,7 @@ tags: analytic_story: - DarkSide Ransomware - Ransomware + - Insider Threat cis20: [] kill_chain_phases: - Exploitation diff --git a/dist/ssa/srs/ssa___fsutil_zeroing_file.yml b/dist/ssa/srs/ssa___fsutil_zeroing_file.yml index 050c17c188..24876e8841 100644 --- a/dist/ssa/srs/ssa___fsutil_zeroing_file.yml +++ b/dist/ssa/srs/ssa___fsutil_zeroing_file.yml @@ -28,6 +28,8 @@ references: tags: analytic_story: - Ransomware + - Insider Threat + - Information Sabotage cis20: [] kill_chain_phases: - Exploitation diff --git a/dist/ssa/srs/ssa___grant_permission_using_cacls_utility.yml b/dist/ssa/srs/ssa___grant_permission_using_cacls_utility.yml index d6dc21e7de..bc15802fc1 100644 --- a/dist/ssa/srs/ssa___grant_permission_using_cacls_utility.yml +++ b/dist/ssa/srs/ssa___grant_permission_using_cacls_utility.yml @@ -28,6 +28,7 @@ references: tags: analytic_story: - XMRig + - Insider Threat cis20: - CIS 14 - CIS 16 diff --git a/dist/ssa/srs/ssa___hiding_files_and_directories_with_attrib_exe.yml b/dist/ssa/srs/ssa___hiding_files_and_directories_with_attrib_exe.yml index 74d6688ac3..44a0c11d93 100644 --- a/dist/ssa/srs/ssa___hiding_files_and_directories_with_attrib_exe.yml +++ b/dist/ssa/srs/ssa___hiding_files_and_directories_with_attrib_exe.yml @@ -31,6 +31,7 @@ tags: - Windows Defense Evasion Tactics - Windows Persistence Techniques - Information Sabotage + - Insider Threat cis20: - CIS 14 - CIS 16 diff --git a/dist/ssa/srs/ssa___wevtutil_usage_to_clear_logs.yml b/dist/ssa/srs/ssa___wevtutil_usage_to_clear_logs.yml index 8017f3c543..93652eed5e 100644 --- a/dist/ssa/srs/ssa___wevtutil_usage_to_clear_logs.yml +++ b/dist/ssa/srs/ssa___wevtutil_usage_to_clear_logs.yml @@ -33,6 +33,7 @@ tags: - Windows Log Manipulation - Ransomware - Clop Ransomware + - Insider Threat cis20: - CIS 8 - CIS 13 diff --git a/dist/ssa/srs/ssa___wevtutil_usage_to_disable_logs.yml b/dist/ssa/srs/ssa___wevtutil_usage_to_disable_logs.yml index 287252279e..793f4a5bb2 100644 --- a/dist/ssa/srs/ssa___wevtutil_usage_to_disable_logs.yml +++ b/dist/ssa/srs/ssa___wevtutil_usage_to_disable_logs.yml @@ -29,6 +29,8 @@ tags: analytic_story: - Windows Log Manipulation - Ransomware + - Insider Threat + - Information Sabotage cis20: - CIS 8 - CIS 13 diff --git a/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml b/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml index eb828d2278..54d3163ba8 100644 --- a/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml +++ b/dist/ssa/srs/ssa___windows_curl_upload_to_remote_destination.yml @@ -47,6 +47,7 @@ references: tags: analytic_story: - Ingress Tool Transfer + - Insider Threat cis20: [] kill_chain_phases: - Exploitation