From 1ec15cf0447c06fcc80971cd38ccb93cdd3bfc82 Mon Sep 17 00:00:00 2001 From: divious1 Date: Mon, 8 Feb 2021 10:18:16 -0500 Subject: [PATCH] renamed on all detections --- .../email_files_written_outside_of_the_outlook_directory.yml | 2 +- ...ple_okta_users_with_invalid_credentails_from_the_same_ip.yml | 2 +- detections/application/okta_account_lockout_events.yml | 2 +- detections/application/okta_failed_sso_attempts.yml | 2 +- .../application/okta_user_logins_from_multiple_cities.yml | 2 +- .../application/web_servers_executing_suspicious_processes.yml | 2 +- detections/cloud/abnormally_high_cloud_instances_destroyed.yml | 2 +- detections/cloud/abnormally_high_cloud_instances_launched.yml | 2 +- ...abnormally_high_number_of_cloud_infrastructure_api_calls.yml | 2 +- ...abnormally_high_number_of_cloud_security_group_api_calls.yml | 2 +- ...ws_cross_account_activity_from_previously_unseen_account.yml | 2 +- ...tect_users_creating_keys_with_encrypt_policy_without_mfa.yml | 2 +- .../aws_detect_users_with_kms_keys_performing_encryption_s3.yml | 2 +- ..._network_access_control_list_created_with_all_open_ports.yml | 2 +- detections/cloud/aws_network_access_control_list_deleted.yml | 2 +- .../cloud/cloud_api_calls_from_previously_unseen_user_roles.yml | 2 +- ...cloud_compute_instance_created_by_previously_unseen_user.yml | 2 +- ...oud_compute_instance_created_in_previously_unused_region.yml | 2 +- ...ud_compute_instance_created_with_previously_unseen_image.yml | 2 +- ...te_instance_created_with_previously_unseen_instance_type.yml | 2 +- .../cloud_instance_modified_with_previously_unseen_user.yml | 2 +- .../cloud/cloud_provisioning_from_previously_unseen_city.yml | 2 +- .../cloud/cloud_provisioning_from_previously_unseen_country.yml | 2 +- .../cloud_provisioning_from_previously_unseen_ip_address.yml | 2 +- .../cloud/cloud_provisioning_from_previously_unseen_region.yml | 2 +- detections/cloud/detect_aws_console_login_by_new_user.yml | 2 +- .../cloud/detect_aws_console_login_by_user_from_new_city.yml | 2 +- .../cloud/detect_aws_console_login_by_user_from_new_country.yml | 2 +- .../cloud/detect_aws_console_login_by_user_from_new_region.yml | 2 +- detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml | 2 +- detections/cloud/detect_new_open_gcp_storage_buckets.yml | 2 +- detections/cloud/detect_new_open_s3_buckets.yml | 2 +- detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml | 2 +- detections/cloud/detect_s3_access_from_a_new_ip.yml | 2 +- ...detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml | 2 +- .../cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml | 2 +- .../detect_spike_in_blocked_outbound_traffic_from_your_aws.yml | 2 +- detections/cloud/detect_spike_in_s3_bucket_deletion.yml | 2 +- .../high_number_of_login_failures_from_a_single_source.yml | 2 +- detections/cloud/new_container_uploaded_to_aws_ecr.yml | 2 +- detections/cloud/o365_bypass_mfa_via_trusted_ip.yml | 2 +- detections/cloud/o365_disable_mfa.yml | 2 +- .../cloud/o365_excessive_authentication_failures_alert.yml | 2 +- detections/cloud/o365_pst_export_alert.yml | 2 +- detections/cloud/o365_suspicious_admin_email_forwarding.yml | 2 +- detections/cloud/o365_suspicious_rights_delegation.yml | 2 +- detections/cloud/o365_suspicious_user_email_forwarding.yml | 2 +- .../abnormally_high_aws_instances_launched_by_user.yml | 2 +- .../abnormally_high_aws_instances_launched_by_user___mltk.yml | 2 +- .../abnormally_high_aws_instances_terminated_by_user.yml | 2 +- .../abnormally_high_aws_instances_terminated_by_user___mltk.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_city.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_country.yml | 2 +- ...aws_cloud_provisioning_from_previously_unseen_ip_address.yml | 2 +- .../aws_cloud_provisioning_from_previously_unseen_region.yml | 2 +- .../deprecated/clients_connecting_to_multiple_dns_servers.yml | 2 +- .../deprecated/cloud_network_access_control_list_deleted.yml | 2 +- .../deprecated/detect_api_activity_from_users_without_mfa.yml | 2 +- .../detect_aws_api_activities_from_unapproved_accounts.yml | 2 +- ...tect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml | 2 +- detections/deprecated/detect_long_dns_txt_record_response.yml | 2 +- detections/deprecated/detect_mimikatz_using_loaded_images.yml | 2 +- detections/deprecated/detect_new_api_calls_from_user_roles.yml | 2 +- detections/deprecated/detect_new_user_aws_console_login.yml | 2 +- detections/deprecated/detect_spike_in_aws_api_activity.yml | 2 +- detections/deprecated/detect_spike_in_network_acl_activity.yml | 2 +- .../deprecated/detect_spike_in_security_group_activity.yml | 2 +- detections/deprecated/detect_usb_device_insertion.yml | 2 +- .../detect_web_traffic_to_dynamic_domain_providers.yml | 2 +- detections/deprecated/detection_of_dns_tunnels.yml | 2 +- .../dns_query_requests_resolved_by_unauthorized_dns_servers.yml | 2 +- .../ec2_instance_modified_with_previously_unseen_user.yml | 2 +- .../ec2_instance_started_in_previously_unseen_region.yml | 2 +- .../ec2_instance_started_with_previously_unseen_ami.yml | 2 +- ...c2_instance_started_with_previously_unseen_instance_type.yml | 2 +- .../ec2_instance_started_with_previously_unseen_user.yml | 2 +- .../execution_of_file_with_spaces_before_extension.yml | 2 +- .../extended_period_without_successful_netbackup_backups.yml | 2 +- detections/deprecated/first_time_seen_command_line_argument.yml | 2 +- detections/deprecated/gcp_gcr_container_uploaded.yml | 2 +- detections/deprecated/identify_new_user_accounts.yml | 2 +- ...ell_process___multiple_suspicious_command_line_arguments.yml | 2 +- detections/deprecated/monitor_dns_for_brand_abuse.yml | 2 +- detections/deprecated/open_redirect_in_splunk_web.yml | 2 +- detections/deprecated/osquery_pack___coldroot_detection.yml | 2 +- detections/deprecated/processes_created_by_netsh.yml | 2 +- detections/deprecated/prohibited_software_on_endpoint.yml | 2 +- ...reg_exe_used_to_hide_files_directories_via_registry_keys.yml | 2 +- detections/deprecated/remote_registry_key_modifications.yml | 2 +- detections/deprecated/remote_wmi_command_attempt.yml | 2 +- .../deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml | 2 +- .../deprecated/splunk_enterprise_information_disclosure.yml | 2 +- .../deprecated/suspicious_changes_to_file_associations.yml | 2 +- detections/deprecated/suspicious_file_write.yml | 2 +- .../suspicious_writes_to_system_volume_information.yml | 2 +- detections/deprecated/uncommon_processes_on_endpoint.yml | 2 +- detections/deprecated/unsigned_image_loaded_by_lsass.yml | 2 +- detections/deprecated/unsuccessful_netbackup_backups.yml | 2 +- detections/deprecated/windows_connhost_exe_force_flag.yml | 2 +- detections/deprecated/windows_disableantispyware_reg.yml | 2 +- detections/deprecated/windows_hosts_file_modification.yml | 2 +- detections/endpoint/access_lsass_memory_for_dump_creation.yml | 2 +- .../endpoint/attempt_to_add_certificate_to_untrusted_store.yml | 2 +- ...lt_powershell_execution_policy_to_unrestricted_or_bypass.yml | 2 +- detections/endpoint/attempt_to_stop_security_service.yml | 2 +- .../attempted_credential_dump_from_registry_via_reg_exe.yml | 2 +- detections/endpoint/batch_file_write_to_system32.yml | 2 +- detections/endpoint/bcdedit_failure_recovery_modification.yml | 2 +- detections/endpoint/common_ransomware_extensions.yml | 2 +- detections/endpoint/common_ransomware_notes.yml | 2 +- .../endpoint/create_local_admin_accounts_using_net_exe.yml | 2 +- .../endpoint/create_or_delete_windows_shares_using_net_exe.yml | 2 +- detections/endpoint/create_remote_thread_into_lsass.yml | 2 +- detections/endpoint/creation_of_shadow_copy.yml | 2 +- .../creation_of_shadow_copy_with_wmic_and_powershell.yml | 2 +- .../credential_dumping_via_copy_command_from_shadow_copy.yml | 2 +- .../endpoint/credential_dumping_via_symlink_to_shadow_copy.yml | 2 +- detections/endpoint/deleting_shadow_copies.yml | 2 +- .../detect_activity_related_to_pass_the_hash_attacks.yml | 2 +- .../endpoint/detect_computer_changed_with_anonymous_account.yml | 2 +- .../endpoint/detect_credential_dumping_through_lsass_access.yml | 2 +- .../detect_excessive_account_lockouts_from_endpoint.yml | 2 +- detections/endpoint/detect_excessive_user_account_lockouts.yml | 2 +- detections/endpoint/detect_mshta_inline_hta_execution.yml | 2 +- detections/endpoint/detect_mshta_renamed.yml | 2 +- detections/endpoint/detect_mshta_url_in_command_line.yml | 2 +- detections/endpoint/detect_new_local_admin_account.yml | 2 +- .../detect_path_interception_by_creation_of_program_exe.yml | 2 +- ...rocesses_used_for_system_network_configuration_discovery.yml | 2 +- .../detect_prohibited_applications_spawning_cmd_exe.yml | 2 +- detections/endpoint/detect_psexec_with_accepteula_flag.yml | 2 +- detections/endpoint/detect_rare_executables.yml | 2 +- detections/endpoint/detect_rundll32_inline_hta_execution.yml | 2 +- .../detect_use_of_cmd_exe_to_launch_script_interpreters.yml | 2 +- detections/endpoint/disabling_remote_user_account_control.yml | 2 +- detections/endpoint/dump_lsass_via_comsvcs_dll.yml | 2 +- .../endpoint/execution_of_file_with_multiple_extensions.yml | 2 +- detections/endpoint/file_with_samsam_extension.yml | 2 +- detections/endpoint/first_time_seen_child_process_of_zoom.yml | 2 +- .../endpoint/hiding_files_and_directories_with_attrib_exe.yml | 2 +- .../endpoint/kerberoasting_spn_request_with_rc4_encryption.yml | 2 +- ...ershell_process___connect_to_internet_with_hidden_window.yml | 2 +- .../endpoint/malicious_powershell_process___encoded_command.yml | 2 +- .../malicious_powershell_process___execution_policy_bypass.yml | 2 +- ...malicious_powershell_process_with_obfuscation_techniques.yml | 2 +- .../endpoint/monitor_registry_keys_for_print_monitors.yml | 2 +- detections/endpoint/nltest_domain_trust_discovery.yml | 2 +- detections/endpoint/overwriting_accessibility_binaries.yml | 2 +- .../process_creating_lnk_file_in_suspicious_location.yml | 2 +- detections/endpoint/process_execution_via_wmi.yml | 2 +- detections/endpoint/processes_launching_netsh.yml | 2 +- .../reg_exe_manipulating_windows_services_registry_keys.yml | 2 +- .../endpoint/registry_keys_for_creating_shim_databases.yml | 2 +- detections/endpoint/registry_keys_used_for_persistence.yml | 2 +- .../endpoint/registry_keys_used_for_privilege_escalation.yml | 2 +- detections/endpoint/remote_process_instantiation_via_wmi.yml | 2 +- detections/endpoint/rundll_loading_dll_by_ordinal.yml | 2 +- detections/endpoint/ryuk_test_files_detected.yml | 2 +- detections/endpoint/samsam_test_file_write.yml | 2 +- detections/endpoint/sc_exe_manipulating_windows_services.yml | 2 +- .../endpoint/scheduled_task_deleted_or_created_via_cmd.yml | 2 +- .../endpoint/schtasks_scheduling_job_on_remote_system.yml | 2 +- detections/endpoint/schtasks_used_for_forcing_a_reboot.yml | 2 +- detections/endpoint/script_execution_via_wmi.yml | 2 +- detections/endpoint/shim_database_file_creation.yml | 2 +- .../shim_database_installation_with_suspicious_parameters.yml | 2 +- detections/endpoint/short_lived_windows_accounts.yml | 2 +- detections/endpoint/single_letter_process_on_endpoint.yml | 2 +- ...sa___attempted_credential_dump_from_registry_via_reg_exe.yml | 2 +- .../endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml | 2 +- .../endpoint/suspicious_microsoft_workflow_compiler_rename.yml | 2 +- .../endpoint/suspicious_microsoft_workflow_compiler_usage.yml | 2 +- detections/endpoint/suspicious_msbuild_path.yml | 2 +- detections/endpoint/suspicious_msbuild_rename.yml | 2 +- detections/endpoint/suspicious_msbuild_spawn.yml | 2 +- detections/endpoint/suspicious_mshta_child_process.yml | 2 +- detections/endpoint/suspicious_mshta_spawn.yml | 2 +- detections/endpoint/suspicious_reg_exe_process.yml | 2 +- detections/endpoint/suspicious_wevtutil_usage.yml | 2 +- .../endpoint/suspicious_writes_to_windows_recycle_bin.yml | 2 +- detections/endpoint/system_information_discovery_detection.yml | 2 +- .../endpoint/system_processes_run_from_unexpected_locations.yml | 2 +- detections/endpoint/unload_sysmon_filter_driver.yml | 2 +- detections/endpoint/unusually_long_command_line.yml | 2 +- detections/endpoint/unusually_long_command_line___mltk.yml | 2 +- detections/endpoint/usn_journal_deletion.yml | 2 +- detections/endpoint/wbadmin_delete_system_backups.yml | 2 +- detections/endpoint/windows_adfind_exe.yml | 2 +- detections/endpoint/windows_event_log_cleared.yml | 2 +- .../endpoint/windows_security_account_manager_stopped.yml | 2 +- .../endpoint/wmi_permanent_event_subscription___sysmon.yml | 2 +- .../application/detect_new_login_attempts_to_routers.yml | 2 +- .../application/email_attachments_with_lots_of_spaces.yml | 2 +- .../email_servers_sending_high_volume_traffic_to_hosts.yml | 2 +- .../experimental/application/monitor_email_for_brand_abuse.yml | 2 +- .../application/no_windows_updates_in_a_time_frame.yml | 2 +- .../application/spectre_and_meltdown_vulnerable_systems.yml | 2 +- .../experimental/application/suspicious_email___uba_anomaly.yml | 2 +- .../application/suspicious_email_attachment_extensions.yml | 2 +- detections/experimental/application/suspicious_java_classes.yml | 2 +- .../cloud/amazon_eks_kubernetes_cluster_scan_detection.yml | 2 +- .../cloud/amazon_eks_kubernetes_pod_scan_detection.yml | 2 +- .../experimental/cloud/aws_detect_attach_to_role_policy.yml | 2 +- .../experimental/cloud/aws_detect_permanent_key_creation.yml | 2 +- detections/experimental/cloud/aws_detect_role_creation.yml | 2 +- .../experimental/cloud/aws_detect_sts_assume_role_abuse.yml | 2 +- .../cloud/aws_detect_sts_get_session_token_abuse.yml | 2 +- .../gcp_detect_accounts_with_high_risk_roles_by_project.yml | 2 +- detections/experimental/cloud/gcp_detect_gcploit_framework.yml | 2 +- ...gcp_detect_high_risk_permissions_by_resource_and_account.yml | 2 +- detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml | 2 +- .../cloud/gcp_kubernetes_cluster_pod_scan_detection.yml | 2 +- .../cloud/gcp_kubernetes_cluster_scan_detection.yml | 2 +- ...ubernetes_aws_detect_most_active_service_accounts_by_pod.yml | 2 +- .../kubernetes_aws_detect_rbac_authorizations_by_account.yml | 2 +- .../cloud/kubernetes_aws_detect_sensitive_object_access.yml | 2 +- .../cloud/kubernetes_aws_detect_sensitive_role_access.yml | 2 +- ...tes_aws_detect_service_accounts_forbidden_failure_access.yml | 2 +- .../cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml | 2 +- ...ure_detect_most_active_service_accounts_by_pod_namespace.yml | 2 +- .../kubernetes_azure_detect_rbac_authorization_by_account.yml | 2 +- .../cloud/kubernetes_azure_detect_sensitive_object_access.yml | 2 +- .../cloud/kubernetes_azure_detect_sensitive_role_access.yml | 2 +- ...s_azure_detect_service_accounts_forbidden_failure_access.yml | 2 +- .../cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml | 2 +- .../cloud/kubernetes_azure_pod_scan_fingerprint.yml | 2 +- .../experimental/cloud/kubernetes_azure_scan_fingerprint.yml | 2 +- .../kubernetes_gcp_detect_RBAC_authorizations_by_account.yml | 2 +- ...ubernetes_gcp_detect_most_active_service_accounts_by_pod.yml | 2 +- .../cloud/kubernetes_gcp_detect_sensitive_object_access.yml | 2 +- .../cloud/kubernetes_gcp_detect_sensitive_role_access.yml | 2 +- ...tes_gcp_detect_service_accounts_forbidden_failure_access.yml | 2 +- .../cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml | 2 +- .../experimental/endpoint/child_processes_of_spoolsv_exe.yml | 2 +- .../endpoint/detect_baron_samedit_cve_2021_3156.yml | 2 +- .../endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml | 2 +- .../endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml | 2 +- .../endpoint/detect_oulook_exe_writing_a__zip_file.yml | 2 +- .../endpoint/detection_of_tools_built_by_nirsoft.yml | 2 +- .../endpoint/first_time_seen_running_windows_service.yml | 2 +- .../experimental/endpoint/processes_tapping_keyboard_events.yml | 2 +- .../endpoint/remote_desktop_process_running_on_system.yml | 2 +- detections/experimental/endpoint/spike_in_file_writes.yml | 2 +- .../endpoint/sunburst_correlation_dll_and_network_event.yml | 2 +- .../experimental/endpoint/wmi_permanent_event_subscription.yml | 2 +- .../experimental/endpoint/wmi_temporary_event_subscription.yml | 2 +- detections/experimental/network/detect_arp_poisoning.yml | 2 +- detections/experimental/network/dns_record_changed.yml | 2 +- detections/experimental/network/excessive_dns_failures.yml | 2 +- ...ceiving_high_volume_of_network_traffic_from_email_server.yml | 2 +- .../experimental/network/large_volume_of_dns_any_queries.yml | 2 +- .../experimental/network/prohibited_network_traffic_allowed.yml | 2 +- detections/experimental/network/protocol_or_port_mismatch.yml | 2 +- .../network/protocols_passing_authentication_in_cleartext.yml | 2 +- .../detect_attackers_scanning_for_vulnerable_jboss_servers.yml | 2 +- .../experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml | 2 +- .../web/detect_malicious_requests_to_exploit_jboss_servers.yml | 2 +- .../experimental/web/monitor_web_traffic_for_brand_abuse.yml | 2 +- detections/experimental/web/sql_injection_with_long_urls.yml | 2 +- detections/experimental/web/supernova_webshell.yml | 2 +- .../detect_hosts_connecting_to_dynamic_domain_providers.yml | 2 +- .../network/detect_ipv6_network_infrastructure_threats.yml | 2 +- detections/network/detect_large_outbound_icmp_packets.yml | 2 +- detections/network/detect_outbound_smb_traffic.yml | 2 +- detections/network/detect_port_security_violation.yml | 2 +- detections/network/detect_rogue_dhcp_server.yml | 2 +- detections/network/detect_snicat_sni_exfiltration.yml | 2 +- .../network/detect_software_download_to_network_device.yml | 2 +- detections/network/detect_traffic_mirroring.yml | 2 +- .../network/detect_unauthorized_assets_by_mac_address.yml | 2 +- .../network/detect_windows_dns_sigred_via_splunk_stream.yml | 2 +- detections/network/detect_windows_dns_sigred_via_zeek.yml | 2 +- detections/network/detect_zerologon_via_zeek.yml | 2 +- detections/network/dns_query_length_outliers___mltk.yml | 2 +- .../network/dns_query_length_with_high_standard_deviation.yml | 2 +- detections/network/remote_desktop_network_bruteforce.yml | 2 +- detections/network/remote_desktop_network_traffic.yml | 2 +- detections/network/smb_traffic_spike.yml | 2 +- detections/network/smb_traffic_spike___mltk.yml | 2 +- detections/network/tor_traffic.yml | 2 +- detections/network/unusually_long_content_type_length.yml | 2 +- detections/web/web_fraud___account_harvesting.yml | 2 +- detections/web/web_fraud___anomalous_user_clickspeed.yml | 2 +- detections/web/web_fraud___password_sharing_across_accounts.yml | 2 +- 284 files changed, 284 insertions(+), 284 deletions(-) diff --git a/detections/application/email_files_written_outside_of_the_outlook_directory.yml b/detections/application/email_files_written_outside_of_the_outlook_directory.yml index b3a3215431..f2f3b9c9eb 100644 --- a/detections/application/email_files_written_outside_of_the_outlook_directory.yml +++ b/detections/application/email_files_written_outside_of_the_outlook_directory.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count values(Filesystem.file_ | `drop_dm_object_name("Filesystem")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `email_files_written_outside_of_the_outlook_directory_filter` ' tags: - analytics_story: + analytic_story: - Collection and Staging asset_type: Endpoint cis20: diff --git a/detections/application/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml b/detections/application/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml index 3082bf18c3..dc775f27fb 100644 --- a/detections/application/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml +++ b/detections/application/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml @@ -17,7 +17,7 @@ search: '`okta` outcome.reason=INVALID_CREDENTIALS | rename client.geographicalC city | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search distinct_users > 5| `multiple_okta_users_with_invalid_credentails_from_the_same_ip_filter` ' tags: - analytics_story: + analytic_story: - Suspicious Okta Activity asset_type: Infrastructure cis20: diff --git a/detections/application/okta_account_lockout_events.yml b/detections/application/okta_account_lockout_events.yml index ea1d9a8c60..f319c3286f 100644 --- a/detections/application/okta_account_lockout_events.yml +++ b/detections/application/okta_account_lockout_events.yml @@ -12,7 +12,7 @@ search: '`okta` displayMessage="Max sign in attempts exceeded" | rename client.g as country, client.geographicalContext.state as state, client.geographicalContext.city as city | table _time, user, country, state, city, src_ip | `okta_account_lockout_events_filter` ' tags: - analytics_story: + analytic_story: - Suspicious Okta Activity asset_type: Infrastructure cis20: diff --git a/detections/application/okta_failed_sso_attempts.yml b/detections/application/okta_failed_sso_attempts.yml index 89dca9a463..3f5c18b5f4 100644 --- a/detections/application/okta_failed_sso_attempts.yml +++ b/detections/application/okta_failed_sso_attempts.yml @@ -12,7 +12,7 @@ search: '`okta` displayMessage="User attempted unauthorized access to app" | sta src_ip | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_failed_sso_attempts_filter` ' tags: - analytics_story: + analytic_story: - Suspicious Okta Activity asset_type: Infrastructure cis20: diff --git a/detections/application/okta_user_logins_from_multiple_cities.yml b/detections/application/okta_user_logins_from_multiple_cities.yml index 873dc069ec..11e8dbc419 100644 --- a/detections/application/okta_user_logins_from_multiple_cities.yml +++ b/detections/application/okta_user_logins_from_multiple_cities.yml @@ -18,7 +18,7 @@ search: '`okta` displayMessage="User login to Okta" client.geographicalContext.c as states by user | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `okta_user_logins_from_multiple_cities_filter` | search locations > 1' tags: - analytics_story: + analytic_story: - Suspicious Okta Activity asset_type: Infrastructure cis20: diff --git a/detections/application/web_servers_executing_suspicious_processes.yml b/detections/application/web_servers_executing_suspicious_processes.yml index 70852ff1f9..357aed8043 100644 --- a/detections/application/web_servers_executing_suspicious_processes.yml +++ b/detections/application/web_servers_executing_suspicious_processes.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by Processes.process Processes.process_name, Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `web_servers_executing_suspicious_processes_filter`' tags: - analytics_story: + analytic_story: - Apache Struts Vulnerability asset_type: Web Server cis20: diff --git a/detections/cloud/abnormally_high_cloud_instances_destroyed.yml b/detections/cloud/abnormally_high_cloud_instances_destroyed.yml index 82bb5a1702..312b821f20 100644 --- a/detections/cloud/abnormally_high_cloud_instances_destroyed.yml +++ b/detections/cloud/abnormally_high_cloud_instances_destroyed.yml @@ -26,7 +26,7 @@ search: '| tstats count as instances_destroyed values(All_Changes.object_id) as table _time, user, instances_destroyed, expected_upper_threshold, distance_from_threshold, object_id | `abnormally_high_number_of_cloud_instances_destroyed_filter`' tags: - analytics_story: + analytic_story: - Suspicious Cloud Instance Activities asset_type: Cloud Instance cis20: diff --git a/detections/cloud/abnormally_high_cloud_instances_launched.yml b/detections/cloud/abnormally_high_cloud_instances_launched.yml index d13053cd1f..3189e815aa 100644 --- a/detections/cloud/abnormally_high_cloud_instances_launched.yml +++ b/detections/cloud/abnormally_high_cloud_instances_launched.yml @@ -26,7 +26,7 @@ search: '| tstats count as instances_launched values(All_Changes.object_id) as o _time, user, instances_launched, expected_upper_threshold, distance_from_threshold, object_id | `abnormally_high_number_of_cloud_instances_launched_filter`' tags: - analytics_story: + analytic_story: - Cloud Cryptomining - Suspicious Cloud Instance Activities asset_type: Cloud Instance diff --git a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml index 2d85ec953b..be26a72ed2 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_infrastructure_api_calls.yml @@ -21,7 +21,7 @@ search: '| tstats count as api_calls values(All_Changes.command) as command from = api_calls - expected_upper_threshold | table _time, user, command, api_calls, expected_upper_threshold, distance_from_threshold | `abnormally_high_number_of_cloud_infrastructure_api_calls_filter`' tags: - analytics_story: + analytic_story: - Suspicious Cloud User Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml index a4fed0df8f..08fe83186c 100644 --- a/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml +++ b/detections/cloud/abnormally_high_number_of_cloud_security_group_api_calls.yml @@ -22,7 +22,7 @@ search: '| tstats count as security_group_api_calls values(All_Changes.command) - expected_upper_threshold | table _time, user, command, security_group_api_calls, expected_upper_threshold, distance_from_threshold | `abnormally_high_number_of_cloud_security_group_api_calls_filter`' tags: - analytics_story: + analytic_story: - Suspicious Cloud User Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml b/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml index 8c8c49c570..17d0167a0a 100644 --- a/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml +++ b/detections/cloud/aws_cross_account_activity_from_previously_unseen_account.yml @@ -27,7 +27,7 @@ search: '| tstats min(_time) as firstTime max(_time) as lastTime from datamodel= Activity" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `aws_cross_account_activity_from_previously_unseen_account_filter`' tags: - analytics_story: + analytic_story: - Suspicious Cloud Authentication Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml index 911ad0d2e0..c7680d6b47 100644 --- a/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml +++ b/detections/cloud/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml @@ -23,7 +23,7 @@ search: '`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy | spath inpu eventID awsRegion userIdentity.principalId | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter`' tags: - analytics_story: + analytic_story: - Ransomware Cloud asset_type: AWS Account automated_detection_testing: passed diff --git a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml index 6ad348c953..3db17668bd 100644 --- a/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml +++ b/detections/cloud/aws_detect_users_with_kms_keys_performing_encryption_s3.yml @@ -18,7 +18,7 @@ search: '`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-e values(userAgent) AS userAgent values(region) AS region values(src) AS src by user | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_detect_users_with_kms_keys_performing_encryption_s3_filter`' tags: - analytics_story: + analytic_story: - Ransomware Cloud asset_type: S3 Bucket automated_detection_testing: passed diff --git a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml index 47c0f1bac3..c4877a20d3 100644 --- a/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/aws_network_access_control_list_created_with_all_open_ports.yml @@ -22,7 +22,7 @@ search: '`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetwor requestParameters.portRange.from src userAgent requestParameters.cidrBlock | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_network_access_control_list_created_with_all_open_ports_filter`' tags: - analytics_story: + analytic_story: - AWS Network ACL Activity asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/aws_network_access_control_list_deleted.yml b/detections/cloud/aws_network_access_control_list_deleted.yml index 6b3615867a..45f2938ade 100644 --- a/detections/cloud/aws_network_access_control_list_deleted.yml +++ b/detections/cloud/aws_network_access_control_list_deleted.yml @@ -18,7 +18,7 @@ search: '`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=f userIdentity.principalId eventName requestParameters.egress src userAgent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `aws_network_access_control_list_deleted_filter`' tags: - analytics_story: + analytic_story: - AWS Network ACL Activity asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index 10ac7a7566..1b116faa15 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -23,7 +23,7 @@ search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from d object, command |`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `cloud_api_calls_from_previously_unseen_user_roles_filter`' tags: - analytics_story: + analytic_story: - Suspicious Cloud User Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index bfe1ccff7b..5888f36ecd 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count earliest(_time) as firs | table firstTime, user, dest, count vendor_region | `security_content_ctime(firstTime)` | `cloud_compute_instance_created_by_previously_unseen_user_filter`' tags: - analytics_story: + analytic_story: - Cloud Cryptomining asset_type: Cloud Compute Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index 6551053f5e..058f294763 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -24,7 +24,7 @@ search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime values( "-24h@h") | table firstTime, user, dest, count , vendor_region | `security_content_ctime(firstTime)` | `cloud_compute_instance_created_in_previously_unused_region_filter`' tags: - analytics_story: + analytic_story: - Cloud Cryptomining asset_type: Cloud Compute Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index 90e5d9bc40..af807302db 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -24,7 +24,7 @@ search: '| tstats count earliest(_time) as firstTime, latest(_time) as lastTime OR firstTimeSeenImage > relative_time(now(), "-24h@h") | table firstTime, user, image_id, count, dest | `security_content_ctime(firstTime)` | `cloud_compute_instance_created_with_previously_unseen_image_filter`' tags: - analytics_story: + analytic_story: - Cloud Cryptomining asset_type: Cloud Compute Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index ecb45bbe40..4de0e07318 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -24,7 +24,7 @@ search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime values "-24h@h") | table firstTime, user, dest, count, instance_type | `security_content_ctime(firstTime)` | `cloud_compute_instance_created_with_previously_unseen_instance_type_filter`' tags: - analytics_story: + analytic_story: - Cloud Cryptomining asset_type: Cloud Compute Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index e8f6b76514..d8a5564ef7 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count earliest(_time) as firs OR firstTimeSeenUser > relative_time(now(), "-24h@h") | table firstTime user command object_id count | `security_content_ctime(firstTime)` | `cloud_instance_modified_by_previously_unseen_user_filter`' tags: - analytics_story: + analytic_story: - Suspicious Cloud Instance Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index 9d4a2bb13b..14a9bd46bb 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -37,7 +37,7 @@ search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from d table firstTime, src, City, user, object, command | `cloud_provisioning_activity_from_previously_unseen_city_filter` | `security_content_ctime(firstTime)`' tags: - analytics_story: + analytic_story: - Suspicious Cloud Provisioning Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index 32d91a04c6..33901073c2 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -37,7 +37,7 @@ search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from d Country, user, object, command | `cloud_provisioning_activity_from_previously_unseen_country_filter` | `security_content_ctime(firstTime)`' tags: - analytics_story: + analytic_story: - Suspicious Cloud Provisioning Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index 4c230f6289..804268a60a 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -36,7 +36,7 @@ search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime, value | table firstTime, src, user, object_id, command | `cloud_provisioning_activity_from_previously_unseen_ip_address_filter` | `security_content_ctime(firstTime)`' tags: - analytics_story: + analytic_story: - Suspicious Cloud Provisioning Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index 5318335ff2..e4668c9d82 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -37,7 +37,7 @@ search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from d | table firstTime, src, Region, user, object, command | `cloud_provisioning_activity_from_previously_unseen_region_filter` | `security_content_ctime(firstTime)`' tags: - analytics_story: + analytic_story: - Suspicious Cloud Provisioning Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/detect_aws_console_login_by_new_user.yml b/detections/cloud/detect_aws_console_login_by_new_user.yml index 4728709a0c..f6209cd9dc 100644 --- a/detections/cloud/detect_aws_console_login_by_new_user.yml +++ b/detections/cloud/detect_aws_console_login_by_new_user.yml @@ -25,7 +25,7 @@ search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime from da Time Logging into AWS Console" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `detect_aws_console_login_by_new_user_filter`' tags: - analytics_story: + analytic_story: - Suspicious Cloud Authentication Activities asset_type: AWS Instance automated_detection_testing: passed diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml index 7d4e7594cb..74193af0ea 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml @@ -30,7 +30,7 @@ search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime from da userStatus != "Old User" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table firstTime lastTime user City userStatus userCity | `detect_aws_console_login_by_user_from_new_city_filter`' tags: - analytics_story: + analytic_story: - Suspicious AWS Login Activities - Suspicious Cloud Authentication Activities asset_type: AWS Instance diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml index fc96b779c7..552a776e0c 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml @@ -30,7 +30,7 @@ search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime from da AND userStatus != "Old User" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table firstTime lastTime user Country userStatus userCountry | `detect_aws_console_login_by_user_from_new_country_filter`' tags: - analytics_story: + analytic_story: - Suspicious AWS Login Activities - Suspicious Cloud Authentication Activities asset_type: AWS Instance diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml index b4fdb12055..2e2e22bba7 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml @@ -30,7 +30,7 @@ search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime from da Region" AND userStatus != "Old User" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table firstTime lastTime user Region userStatus userRegion | `detect_aws_console_login_by_user_from_new_region_filter`' tags: - analytics_story: + analytic_story: - Suspicious AWS Login Activities - Suspicious Cloud Authentication Activities asset_type: AWS Instance diff --git a/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml b/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml index ff8e64bd6f..79d4b01aa9 100644 --- a/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml +++ b/detections/cloud/detect_gcp_storage_access_from_a_new_ip.yml @@ -33,7 +33,7 @@ search: '`google_gcp_pubsub_message` | multikv | rename sc_status_ as status | r %H:%M:%S") | eval last_time=strftime(lastTime,"%m/%d/%y %H:%M:%S") | table first_time last_time bucket_name remote_ip operation request_uri | `detect_gcp_storage_access_from_a_new_ip_filter`' tags: - analytics_story: + analytic_story: - Suspicious GCP Storage Activities asset_type: GCP Storage Bucket cis20: diff --git a/detections/cloud/detect_new_open_gcp_storage_buckets.yml b/detections/cloud/detect_new_open_gcp_storage_buckets.yml index a19b1d5bca..03aca91672 100644 --- a/detections/cloud/detect_new_open_gcp_storage_buckets.yml +++ b/detections/cloud/detect_new_open_gcp_storage_buckets.yml @@ -22,7 +22,7 @@ search: '`google_gcp_pubsub_message` data.resource.type=gcs_bucket data.protoPay | search (member=allUsers AND action=ADD) | table _time, bucketName, src, user, location, action, role, member | search `detect_new_open_gcp_storage_buckets_filter`' tags: - analytics_story: + analytic_story: - Suspicious GCP Storage Activities asset_type: GCP Storage Bucket cis20: diff --git a/detections/cloud/detect_new_open_s3_buckets.yml b/detections/cloud/detect_new_open_s3_buckets.yml index 983b8eebed..36834556df 100644 --- a/detections/cloud/detect_new_open_s3_buckets.yml +++ b/detections/cloud/detect_new_open_s3_buckets.yml @@ -20,7 +20,7 @@ search: '`cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl | rex bucketName | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_new_open_s3_buckets_filter` ' tags: - analytics_story: + analytic_story: - Suspicious AWS S3 Activities asset_type: S3 Bucket automated_detection_testing: passed diff --git a/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml b/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml index 0125cbc90a..8a5e0c258c 100644 --- a/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml +++ b/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml @@ -20,7 +20,7 @@ search: '`cloudtrail` eventSource="s3.amazonaws.com" eventName=PutBucketAcl OR r requestParameters.accessControlList.x-amz-grant-write-acp requestParameters.accessControlList.x-amz-grant-full-control | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_new_open_s3_buckets_over_aws_cli_filter` ' tags: - analytics_story: + analytic_story: - Suspicious AWS S3 Activities asset_type: S3 Bucket automated_detection_testing: passed diff --git a/detections/cloud/detect_s3_access_from_a_new_ip.yml b/detections/cloud/detect_s3_access_from_a_new_ip.yml index 54edf60484..901e7b33a4 100644 --- a/detections/cloud/detect_s3_access_from_a_new_ip.yml +++ b/detections/cloud/detect_s3_access_from_a_new_ip.yml @@ -22,7 +22,7 @@ search: '`aws_s3_accesslogs` http_status=200 [search `aws_s3_accesslogs` http_s | table bucket_name remote_ip]| iplocation remote_ip |rename remote_ip as src_ip | table _time bucket_name src_ip City Country operation request_uri | `detect_s3_access_from_a_new_ip_filter`' tags: - analytics_story: + analytic_story: - Suspicious AWS S3 Activities asset_type: S3 Bucket cis20: diff --git a/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml b/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml index 959f4438f2..97d1c1cd2e 100644 --- a/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml +++ b/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_ec2_instance.yml @@ -22,7 +22,7 @@ search: '`aws_securityhub_finding` "Resources{}.Type"=AWSEC2Instance | bucket sp * threshold_value), 1, 0) | search isOutlier=1 | table _time dest alerts Title Types vendor_account vendor_region severity isOutlier total_alerts_avg | `detect_spike_in_aws_security_hub_alerts_for_ec2_instance_filter`' tags: - analytics_story: + analytic_story: - AWS Security Hub Alerts asset_type: AWS Instance cis20: diff --git a/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml b/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml index b0350e2dd1..fc6b8e4734 100644 --- a/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml +++ b/detections/cloud/detect_spike_in_aws_security_hub_alerts_for_user.yml @@ -21,7 +21,7 @@ search: '`aws_securityhub_finding` "findings{}.Resources{}.Type"= AwsIamUser | r | search isOutlier=1 | table _time user alerts |`detect_spike_in_aws_security_hub_alerts_for_user_filter`' tags: - analytics_story: + analytic_story: - AWS Security Hub Alerts asset_type: AWS Instance cis20: diff --git a/detections/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml b/detections/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml index 8dc034146f..ff8d07f46e 100644 --- a/detections/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml +++ b/detections/cloud/detect_spike_in_blocked_outbound_traffic_from_your_aws.yml @@ -38,7 +38,7 @@ search: '`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=17 count as numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip | `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter`' tags: - analytics_story: + analytic_story: - AWS Network ACL Activity - Suspicious AWS Traffic - Command and Control diff --git a/detections/cloud/detect_spike_in_s3_bucket_deletion.yml b/detections/cloud/detect_spike_in_s3_bucket_deletion.yml index 38cac25192..3f606f8a3e 100644 --- a/detections/cloud/detect_spike_in_s3_bucket_deletion.yml +++ b/detections/cloud/detect_spike_in_s3_bucket_deletion.yml @@ -32,7 +32,7 @@ search: '`cloudtrail` eventName=DeleteBucket [search `cloudtrail` eventName=Dele path=requestParameters.bucketName | stats values(bucketName) as bucketName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user | `detect_spike_in_s3_bucket_deletion_filter`' tags: - analytics_story: + analytic_story: - Suspicious AWS S3 Activities asset_type: S3 Bucket cis20: diff --git a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml index db8f3d2d57..5ef13dcb3b 100644 --- a/detections/cloud/high_number_of_login_failures_from_a_single_source.yml +++ b/detections/cloud/high_number_of_login_failures_from_a_single_source.yml @@ -12,7 +12,7 @@ search: '`o365_management_activity` Operation=UserLoginFailed record_type=Azure values(signature) as signature values(UserAgent) as UserAgent by src_ip record_type Operation app | search accounts_locked >= 5| `high_number_of_login_failures_from_a_single_source_filter`' tags: - analytics_story: + analytic_story: - Office 365 Detections asset_type: Office 365 cis20: diff --git a/detections/cloud/new_container_uploaded_to_aws_ecr.yml b/detections/cloud/new_container_uploaded_to_aws_ecr.yml index 241e0ec268..e20b2a5a5f 100644 --- a/detections/cloud/new_container_uploaded_to_aws_ecr.yml +++ b/detections/cloud/new_container_uploaded_to_aws_ecr.yml @@ -18,7 +18,7 @@ search: '| tstats count min(_time) as firstTime max(_time) as lastTime FROM data Compute.region Compute.msg Compute.user_type | `drop_dm_object_name("Compute")` | `new_container_uploaded_to_aws_ecr_filter` ' tags: - analytics_story: + analytic_story: - Container Implantation Monitoring and Investigation asset_type: AWS ECR container mitre_attack_id: diff --git a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml index 24a82284d7..45f175e462 100644 --- a/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml +++ b/detections/cloud/o365_bypass_mfa_via_trusted_ip.yml @@ -22,7 +22,7 @@ search: '`o365_management_activity` signature="Set Company Information." Modifie status user_id action | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `o365_bypass_mfa_via_trusted_ip_filter`' tags: - analytics_story: + analytic_story: - Office 365 Detections asset_type: Office 365 automated_detection_testing: passed diff --git a/detections/cloud/o365_disable_mfa.yml b/detections/cloud/o365_disable_mfa.yml index 45bc1424eb..90a1882d45 100644 --- a/detections/cloud/o365_disable_mfa.yml +++ b/detections/cloud/o365_disable_mfa.yml @@ -15,7 +15,7 @@ search: '`o365_management_activity` Operation="Disable Strong Authentication." | user status signature dest ResultStatus |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `o365_disable_mfa_filter`' tags: - analytics_story: + analytic_story: - Office 365 Detections asset_type: Office 365 automated_detection_testing: passed diff --git a/detections/cloud/o365_excessive_authentication_failures_alert.yml b/detections/cloud/o365_excessive_authentication_failures_alert.yml index fe1899ed67..1338dd6400 100644 --- a/detections/cloud/o365_excessive_authentication_failures_alert.yml +++ b/detections/cloud/o365_excessive_authentication_failures_alert.yml @@ -16,7 +16,7 @@ search: '`o365_management_activity` Workload=AzureActiveDirectory UserAuthentica values(src_ip) AS src_ip by user | where count > 10 |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `o365_excessive_authentication_failures_alert_filter`' tags: - analytics_story: + analytic_story: - Office 365 Detections asset_type: Office 365 automated_detection_testing: passed diff --git a/detections/cloud/o365_pst_export_alert.yml b/detections/cloud/o365_pst_export_alert.yml index e6f109db8d..d394762eee 100644 --- a/detections/cloud/o365_pst_export_alert.yml +++ b/detections/cloud/o365_pst_export_alert.yml @@ -16,7 +16,7 @@ search: '`o365_management_activity` Category=ThreatManagement Name="eDiscovery s lastTime by Source Severity AlertEntityId Operation Name |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `o365_pst_export_alert_filter`' tags: - analytics_story: + analytic_story: - Office 365 Detections asset_type: Office 365 automated_detection_testing: passed diff --git a/detections/cloud/o365_suspicious_admin_email_forwarding.yml b/detections/cloud/o365_suspicious_admin_email_forwarding.yml index ace3e83f47..be0336e5f4 100644 --- a/detections/cloud/o365_suspicious_admin_email_forwarding.yml +++ b/detections/cloud/o365_suspicious_admin_email_forwarding.yml @@ -11,7 +11,7 @@ search: '`o365_management_activity` Operation=Set-Mailbox | spath input=Paramete AS src_user values(user) AS user by ForwardingAddress | where count_src_user > 1 |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`o365_suspicious_admin_email_forwarding_filter`' tags: - analytics_story: + analytic_story: - Office 365 Detections asset_type: Office 365 automated_detection_testing: passed diff --git a/detections/cloud/o365_suspicious_rights_delegation.yml b/detections/cloud/o365_suspicious_rights_delegation.yml index 38fc48a87c..f10c3c59b5 100644 --- a/detections/cloud/o365_suspicious_rights_delegation.yml +++ b/detections/cloud/o365_suspicious_rights_delegation.yml @@ -11,7 +11,7 @@ search: '`o365_management_activity` Operation=Add-MailboxPermission | spath inpu as firstTime latest(_time) as lastTime by user src_user dest_user Operation AccessRights |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`o365_suspicious_rights_delegation_filter`' tags: - analytics_story: + analytic_story: - Office 365 Detections asset_type: Office 365 automated_detection_testing: passed diff --git a/detections/cloud/o365_suspicious_user_email_forwarding.yml b/detections/cloud/o365_suspicious_user_email_forwarding.yml index 0c17f9729b..b3398452c8 100644 --- a/detections/cloud/o365_suspicious_user_email_forwarding.yml +++ b/detections/cloud/o365_suspicious_user_email_forwarding.yml @@ -11,7 +11,7 @@ search: '`o365_management_activity` Operation=Set-Mailbox | spath input=Paramete AS src_user values(user) AS user by ForwardingSmtpAddress | where count_src_user > 1 |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`o365_suspicious_user_email_forwarding_filter`' tags: - analytics_story: + analytic_story: - Office 365 Detections asset_type: Office 365 automated_detection_testing: passed diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml index 1f03202df6..12d952d73a 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml @@ -22,7 +22,7 @@ search: '`cloudtrail` eventName=RunInstances errorCode=success | bucket span=10m / total_launched_stdev, 2) | table _time, userName, instances_launched, num_standard_deviations_away, total_launched_avg, total_launched_stdev | `abnormally_high_aws_instances_launched_by_user_filter`' tags: - analytics_story: + analytic_story: - AWS Cryptomining - Suspicious AWS EC2 Activities asset_type: AWS Instance diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml index 8be22a0226..719bed8d1e 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml @@ -18,7 +18,7 @@ search: '`cloudtrail` eventName=RunInstances errorCode=success `abnormally_high_ apply ec2_excessive_runinstances_v1 | rename "IsOutlier(instances_launched)" as isOutlier | where isOutlier=1' tags: - analytics_story: + analytic_story: - AWS Cryptomining - Suspicious AWS EC2 Activities asset_type: AWS Instance diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml index 8656647a11..0fa3fcd896 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml @@ -23,7 +23,7 @@ search: '`cloudtrail` eventName=TerminateInstances errorCode=success | bucket sp num_standard_deviations_away, total_terminations_avg, total_terminations_stdev | `abnormally_high_aws_instances_terminated_by_user_filter`' tags: - analytics_story: + analytic_story: - Suspicious AWS EC2 Activities asset_type: AWS Instance cis20: diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml index 5d7d9cd1a0..1371ddf7bb 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml @@ -18,7 +18,7 @@ search: '`cloudtrail` eventName=TerminateInstances errorCode=success `abnormally apply ec2_excessive_terminateinstances_v1 | rename "IsOutlier(instances_terminated)" as isOutlier | where isOutlier=1' tags: - analytics_story: + analytic_story: - Suspicious AWS EC2 Activities asset_type: AWS Instance cis20: diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml index c95f47d4c9..2a51330c4a 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -34,7 +34,7 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, City, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_city_filter`' tags: - analytics_story: + analytic_story: - AWS Suspicious Provisioning Activities asset_type: AWS Instance cis20: diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml index 305502d129..8eac869202 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -35,7 +35,7 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, Country, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter`' tags: - analytics_story: + analytic_story: - AWS Suspicious Provisioning Activities asset_type: AWS Instance cis20: diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml index 2ab91cc70c..ea85851ba6 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml @@ -34,7 +34,7 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) [search `cloudtrail` | spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_ip_address_filter`' tags: - analytics_story: + analytic_story: - AWS Suspicious Provisioning Activities asset_type: AWS Instance cis20: diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml index 1fca26816a..29e62606b6 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -34,7 +34,7 @@ search: '`cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceI output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, Region, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_region_filter`' tags: - analytics_story: + analytic_story: - AWS Suspicious Provisioning Activities asset_type: AWS Instance cis20: diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml index b5733747ea..773ea41fa0 100644 --- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml +++ b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml @@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count, values(DNS.dest) AS de by DNS.src | `drop_dm_object_name("Network_Resolution")` |where dest_count > 5 | `clients_connecting_to_multiple_dns_servers_filter` ' tags: - analytics_story: + analytic_story: - DNS Hijacking - Command and Control - Suspicious DNS Traffic diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/detections/deprecated/cloud_network_access_control_list_deleted.yml index b75c29e732..920f268b46 100644 --- a/detections/deprecated/cloud_network_access_control_list_deleted.yml +++ b/detections/deprecated/cloud_network_access_control_list_deleted.yml @@ -19,7 +19,7 @@ search: '`cloudtrail` eventName=DeleteNetworkAcl|rename userIdentity.arn as arn values(errorCode) values(userAgent) values(userIdentity.*) by src userName arn eventName | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `cloud_network_access_control_list_deleted_filter`' tags: - analytics_story: + analytic_story: - Cloud Network ACL Activity asset_type: Instance cis20: diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml index 9fbc63d58a..ad137fa075 100644 --- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml +++ b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml @@ -43,7 +43,7 @@ search: '`cloudtrail` userIdentity.sessionContext.attributes.mfaAuthenticated=fa as eventName by userIdentity.arn userIdentity.type user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_api_activity_from_users_without_mfa_filter`' tags: - analytics_story: + analytic_story: - AWS User Monitoring asset_type: AWS Instance cis20: diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml index 791342bce6..b185be2cdb 100644 --- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml +++ b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml @@ -44,7 +44,7 @@ search: '`cloudtrail` errorCode=success | rename userName as identity | search N user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_aws_api_activities_from_unapproved_accounts_filter`' tags: - analytics_story: + analytic_story: - AWS User Monitoring asset_type: AWS Instance cis20: diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index 642633e7ac..f5013bbec5 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -32,7 +32,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by Web.dest Web.site | rename "Web.*" as * | rex field=site ".*?(?[^./:]+\.(\S{2,3}|\S{2,3}.\S{2,3}))$" | table dest domain url] | table count src dest query answer domain url | `detect_dns_requests_to_phishing_sites_leveraging_evilginx2_filter`' tags: - analytics_story: + analytic_story: - Common Phishing Frameworks asset_type: Endpoint cis20: diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/detections/deprecated/detect_long_dns_txt_record_response.yml index 98e53f8cca..837db579b5 100644 --- a/detections/deprecated/detect_long_dns_txt_record_response.yml +++ b/detections/deprecated/detect_long_dns_txt_record_response.yml @@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime IP" "Destination IP" "DNS Answer" "DNS Record Type" "Answer Length" Count "First Time" "Last Time" | `detect_long_dns_txt_record_response_filter`' tags: - analytics_story: + analytic_story: - Suspicious DNS Traffic - Command and Control asset_type: Endpoint diff --git a/detections/deprecated/detect_mimikatz_using_loaded_images.yml b/detections/deprecated/detect_mimikatz_using_loaded_images.yml index 972f12f659..1016f37f59 100644 --- a/detections/deprecated/detect_mimikatz_using_loaded_images.yml +++ b/detections/deprecated/detect_mimikatz_using_loaded_images.yml @@ -21,7 +21,7 @@ search: '`sysmon` EventCode=7 | stats values(ImageLoaded) as ImageLoaded values( Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_mimikatz_using_loaded_images_filter`' tags: - analytics_story: + analytic_story: - Credential Dumping - Detect Zerologon Attack asset_type: Windows diff --git a/detections/deprecated/detect_new_api_calls_from_user_roles.yml b/detections/deprecated/detect_new_api_calls_from_user_roles.yml index 96df484aea..81fba34960 100644 --- a/detections/deprecated/detect_new_api_calls_from_user_roles.yml +++ b/detections/deprecated/detect_new_api_calls_from_user_roles.yml @@ -24,7 +24,7 @@ search: '`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=A as earliest latest(_time) as latest by user | `security_content_ctime(earliest)` | `security_content_ctime(latest)` | `detect_new_api_calls_from_user_roles_filter`' tags: - analytics_story: + analytic_story: - AWS User Monitoring asset_type: AWS Instance cis20: diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml index 6a0a8cef6d..342a488ecd 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/detections/deprecated/detect_new_user_aws_console_login.yml @@ -23,7 +23,7 @@ search: '`cloudtrail` eventName=ConsoleLogin | rename userIdentity.arn as user | "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| where userStatus ="First Time Logging into AWS Console" | `detect_new_user_aws_console_login_filter`' tags: - analytics_story: + analytic_story: - Suspicious AWS Login Activities asset_type: AWS Instance cis20: diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/detections/deprecated/detect_spike_in_aws_api_activity.yml index 25ef6f8212..9784918f82 100644 --- a/detections/deprecated/detect_spike_in_aws_api_activity.yml +++ b/detections/deprecated/detect_spike_in_aws_api_activity.yml @@ -49,7 +49,7 @@ search: '`cloudtrail` eventType=AwsApiCall [search `cloudtrail` eventType=AwsApi as eventName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user | `detect_spike_in_aws_api_activity_filter`' tags: - analytics_story: + analytic_story: - AWS User Monitoring asset_type: AWS Instance cis20: diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/detections/deprecated/detect_spike_in_network_acl_activity.yml index d2b2d654c1..eb66faff95 100644 --- a/detections/deprecated/detect_spike_in_network_acl_activity.yml +++ b/detections/deprecated/detect_spike_in_network_acl_activity.yml @@ -33,7 +33,7 @@ search: '`cloudtrail` `network_acl_events` [search `cloudtrail` `network_acl_eve | stats values(eventName) as eventNames, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user | `detect_spike_in_network_acl_activity_filter`' tags: - analytics_story: + analytic_story: - AWS Network ACL Activity asset_type: AWS Instance cis20: diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/detections/deprecated/detect_spike_in_security_group_activity.yml index 8f307c7b49..4091497fa3 100644 --- a/detections/deprecated/detect_spike_in_security_group_activity.yml +++ b/detections/deprecated/detect_spike_in_security_group_activity.yml @@ -34,7 +34,7 @@ search: '`cloudtrail` `security_group_api_calls` [search `cloudtrail` `security_ | stats values(eventName) as eventNames, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user | `detect_spike_in_security_group_activity_filter`' tags: - analytics_story: + analytic_story: - AWS User Monitoring asset_type: AWS Instance cis20: diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/detections/deprecated/detect_usb_device_insertion.yml index f940a99585..4cdc36c42d 100644 --- a/detections/deprecated/detect_usb_device_insertion.yml +++ b/detections/deprecated/detect_usb_device_insertion.yml @@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` count earliest(_time) AS earl (All_Changes.src_priority=high) by All_Changes.dest | `drop_dm_object_name("All_Changes")`| `security_content_ctime(earliest)`| `security_content_ctime(latest)` | `detect_usb_device_insertion_filter`' tags: - analytics_story: + analytic_story: - Data Protection asset_type: Endpoint cis20: diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml index b88d511dfc..0868427b68 100644 --- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml +++ b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml @@ -29,7 +29,7 @@ search: '| tstats `security_content_summariesonly` count values(Web.url) as url | `drop_dm_object_name("Web")` | `security_content_ctime(firstTime)` | `dynamic_dns_web_traffic` | `detect_web_traffic_to_dynamic_domain_providers_filter`' tags: - analytics_story: + analytic_story: - Dynamic DNS asset_type: Endpoint cis20: diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/detections/deprecated/detection_of_dns_tunnels.yml index e20f51bb0a..8fe03fd803 100644 --- a/detections/deprecated/detection_of_dns_tunnels.yml +++ b/detections/deprecated/detection_of_dns_tunnels.yml @@ -36,7 +36,7 @@ search: '| tstats `security_content_summariesonly` dc("DNS.query") as count fro message) | eval length=len(message) | stats sum(length) as length by src ] | stats sum(length) as length by src | where length > 10000 | `detection_of_dns_tunnels_filter`' tags: - analytics_story: + analytic_story: - Data Protection - Suspicious DNS Traffic - Command and Control diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml index 1fe05fbc5a..325b570344 100644 --- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml +++ b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml @@ -15,7 +15,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Network_ where DNS.dest_category != dns_server AND DNS.src_category != dns_server by DNS.src DNS.dest | `drop_dm_object_name("DNS")` | `dns_query_requests_resolved_by_unauthorized_dns_servers_filter` ' tags: - analytics_story: + analytic_story: - DNS Hijacking - Command and Control - Suspicious DNS Traffic diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml index 3064059584..896eb44ed5 100644 --- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml @@ -23,7 +23,7 @@ search: '`cloudtrail` `ec2_modification_api_calls` [search `cloudtrail` `ec2_mod | rename arn as userIdentity.arn | table userIdentity.arn] | spath output=dest responseElements.instancesSet.items{}.instanceId | spath output=user userIdentity.arn | table _time, user, dest | `ec2_instance_modified_with_previously_unseen_user_filter`' tags: - analytics_story: + analytic_story: - Unusual AWS EC2 Modifications asset_type: AWS Instance cis20: diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml index 1cf9d75e78..1328415b4e 100644 --- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml +++ b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml @@ -21,7 +21,7 @@ search: '`cloudtrail` earliest=-1h StartInstances | stats earliest(_time) as ear | `security_content_ctime(latest)` | where regionStatus="Instance Started in a New Region" | `ec2_instance_started_in_previously_unseen_region_filter`' tags: - analytics_story: + analytic_story: - AWS Cryptomining - Suspicious AWS EC2 Activities asset_type: AWS Instance diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml index 5fd7e4b3fd..30733708ab 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml @@ -25,7 +25,7 @@ search: '`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunI as arn, requestParameters.instancesSet.items{}.imageId as amiID | table firstTime, lastTime, arn, amiID, dest, instanceType | `ec2_instance_started_with_previously_unseen_ami_filter`' tags: - analytics_story: + analytic_story: - AWS Cryptomining asset_type: AWS Instance cis20: diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml index 1066e0879b..18c333ae4b 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml @@ -25,7 +25,7 @@ search: '`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunI as instanceType, responseElements.instancesSet.items{}.instanceId as dest | table _time, user, dest, instanceType | `ec2_instance_started_with_previously_unseen_instance_type_filter`' tags: - analytics_story: + analytic_story: - AWS Cryptomining asset_type: AWS Instance cis20: diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml index 62e781ea65..b11af83f18 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml @@ -23,7 +23,7 @@ search: '`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunI as instanceType, responseElements.instancesSet.items{}.instanceId as dest, userIdentity.arn as user | table _time, user, dest, instanceType | `ec2_instance_started_with_previously_unseen_user_filter`' tags: - analytics_story: + analytic_story: - AWS Cryptomining - Suspicious AWS EC2 Activities asset_type: AWS Instance diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml index a19d7050b7..2a79a42c73 100644 --- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml +++ b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.process_name | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` | `execution_of_file_with_spaces_before_extension_filter`' tags: - analytics_story: + analytic_story: - Windows File Extension and Association Abuse asset_type: Endpoint cis20: diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml index 0e9c8a92f9..071042bdef 100644 --- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml +++ b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml @@ -17,7 +17,7 @@ search: '`netbackup` MESSAGE="Disk/Partition backup completed successfully." | s | rename COMPUTERNAME as dest | eval isOutlier=if(latestTime <= relative_time(now(), "-7d@d"), 1, 0) | search isOutlier=1 | table latestTime, dest | `extended_period_without_successful_netbackup_backups_filter`' tags: - analytics_story: + analytic_story: - Monitor Backup Solution asset_type: Endpoint cis20: diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/detections/deprecated/first_time_seen_command_line_argument.yml index 402c03adb1..8774ced086 100644 --- a/detections/deprecated/first_time_seen_command_line_argument.yml +++ b/detections/deprecated/first_time_seen_command_line_argument.yml @@ -31,7 +31,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_ "-70m@m"), 1, 0) | where newCmdLineArgument=1 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table process] | `first_time_seen_command_line_argument_filter` ' tags: - analytics_story: + analytic_story: - DHS Report TA18-074A - Suspicious Command-Line Executions - Orangeworm Attack Group diff --git a/detections/deprecated/gcp_gcr_container_uploaded.yml b/detections/deprecated/gcp_gcr_container_uploaded.yml index 4775b9e553..1526f0ec32 100644 --- a/detections/deprecated/gcp_gcr_container_uploaded.yml +++ b/detections/deprecated/gcp_gcr_container_uploaded.yml @@ -19,7 +19,7 @@ search: '|tstats count min(_time) as firstTime max(_time) as lastTime FROM data Storage.action Storage.bucket_name Storage.event_name Storage.http_user_agent Storage.msg Storage.object_path | `drop_dm_object_name("Storage")` | `gcp_gcr_container_uploaded_filter` ' tags: - analytics_story: + analytic_story: - Container Implantation Monitoring and Investigation asset_type: GCP GCR Container mitre_attack_id: diff --git a/detections/deprecated/identify_new_user_accounts.yml b/detections/deprecated/identify_new_user_accounts.yml index b58242148a..62df130be0 100644 --- a/detections/deprecated/identify_new_user_accounts.yml +++ b/detections/deprecated/identify_new_user_accounts.yml @@ -17,7 +17,7 @@ search: '| from datamodel Identity_Management.All_Identities | eval empStatus=c `security_content_ctime(endDate)` | `security_content_ctime(startDate)`| table identity empStatus endDate startDate | `identify_new_user_accounts_filter`' tags: - analytics_story: + analytic_story: - Account Monitoring and Controls asset_type: Domain Server cis20: diff --git a/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml b/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml index f3a660b337..91172eae06 100644 --- a/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml +++ b/detections/deprecated/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml @@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| search (process=*-EncodedCommand* OR process=*-enc*) process=*-Exec* | `malicious_powershell_process___multiple_suspicious_command_line_arguments_filter`' tags: - analytics_story: + analytic_story: - Malicious PowerShell asset_type: Endpoint cis20: diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/detections/deprecated/monitor_dns_for_brand_abuse.yml index 77788d87f7..cb0893230b 100644 --- a/detections/deprecated/monitor_dns_for_brand_abuse.yml +++ b/detections/deprecated/monitor_dns_for_brand_abuse.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` values(DNS.answer) as IPs min as firstTime from datamodel=Network_Resolution by DNS.src, DNS.query | `drop_dm_object_name("DNS")` | `security_content_ctime(firstTime)`| `brand_abuse_dns` | `monitor_dns_for_brand_abuse_filter`' tags: - analytics_story: + analytic_story: - Brand Monitoring asset_type: Endpoint kill_chain_phases: diff --git a/detections/deprecated/open_redirect_in_splunk_web.yml b/detections/deprecated/open_redirect_in_splunk_web.yml index 8f27f532ca..d561778edc 100644 --- a/detections/deprecated/open_redirect_in_splunk_web.yml +++ b/detections/deprecated/open_redirect_in_splunk_web.yml @@ -9,7 +9,7 @@ name: Open Redirect in Splunk Web references: [] search: index=_internal sourcetype=splunk_web_access return_to="/%09/*" | `open_redirect_in_splunk_web_filter` tags: - analytics_story: + analytic_story: - Splunk Enterprise Vulnerability asset_type: Splunk Server cis20: diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml index 24deb4f510..04942260d5 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/detections/deprecated/osquery_pack___coldroot_detection.yml @@ -14,7 +14,7 @@ search: '| from datamodel Alerts.Alerts | search app=osquery:results (name=pack_ OR name=pack_osx-attacks_OSX_ColdRoot_RAT_Files) | rename columns.path as path | bucket _time span=30s | stats count(path) by _time, host, user, path | `osquery_pack___coldroot_detection_filter`' tags: - analytics_story: + analytic_story: - ColdRoot MacOS RAT asset_type: Endpoint cis20: diff --git a/detections/deprecated/processes_created_by_netsh.yml b/detections/deprecated/processes_created_by_netsh.yml index 24f2f38c5f..8aa68f507e 100644 --- a/detections/deprecated/processes_created_by_netsh.yml +++ b/detections/deprecated/processes_created_by_netsh.yml @@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.parent_process_name Processes.process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `processes_created_by_netsh_filter`' tags: - analytics_story: + analytic_story: - Netsh Abuse asset_type: Endpoint cis20: diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/detections/deprecated/prohibited_software_on_endpoint.yml index 9094b73286..b947e40abb 100644 --- a/detections/deprecated/prohibited_software_on_endpoint.yml +++ b/detections/deprecated/prohibited_software_on_endpoint.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` | `prohibited_softwares` | `prohibited_software_on_endpoint_filter`' tags: - analytics_story: + analytic_story: - Monitor for Unauthorized Software - 'Emotet Malware DHS Report TA18-201A ' - SamSam Ransomware diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml index 3201c0435a..d3e4722069 100644 --- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml +++ b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)`| regex process = "(/d\s+2)" | `reg_exe_used_to_hide_files_directories_via_registry_keys_filter`' tags: - analytics_story: + analytic_story: - Windows Defense Evasion Tactics - Suspicious Windows Registry Activities - Windows Persistence Techniques diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/detections/deprecated/remote_registry_key_modifications.yml index 59990fd6d7..4c8c5bea96 100644 --- a/detections/deprecated/remote_registry_key_modifications.yml +++ b/detections/deprecated/remote_registry_key_modifications.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count values(Registry.registr Registry.dest , Registry.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `remote_registry_key_modifications_filter`' tags: - analytics_story: + analytic_story: - Windows Defense Evasion Tactics - Suspicious Windows Registry Activities - Windows Persistence Techniques diff --git a/detections/deprecated/remote_wmi_command_attempt.yml b/detections/deprecated/remote_wmi_command_attempt.yml index be0f06b215..9d3db6ff24 100644 --- a/detections/deprecated/remote_wmi_command_attempt.yml +++ b/detections/deprecated/remote_wmi_command_attempt.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `remote_wmi_command_attempt_filter`' tags: - analytics_story: + analytic_story: - Suspicious WMI Use asset_type: Endpoint cis20: diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml index 666ee9e234..ccb8b5efb8 100644 --- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | search (process=*rhaegal* OR process=*drogon* OR *viserion_*) | `scheduled_tasks_used_in_badrabbit_ransomware_filter`' tags: - analytics_story: + analytic_story: - Ransomware asset_type: Endpoint cis20: diff --git a/detections/deprecated/splunk_enterprise_information_disclosure.yml b/detections/deprecated/splunk_enterprise_information_disclosure.yml index 3fd5f6302c..3e4d630c65 100644 --- a/detections/deprecated/splunk_enterprise_information_disclosure.yml +++ b/detections/deprecated/splunk_enterprise_information_disclosure.yml @@ -16,7 +16,7 @@ search: index=_internal sourcetype=splunkd_ui_access server-info | search client as uri, values(useragent) as http_user_agent, values(user) as user by src_ip, dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `splunk_enterprise_information_disclosure_filter` tags: - analytics_story: + analytic_story: - Splunk Enterprise Vulnerability CVE-2018-11409 asset_type: Splunk Server cis20: diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/detections/deprecated/suspicious_changes_to_file_associations.yml index 52b16a9d3d..6f4002a10e 100644 --- a/detections/deprecated/suspicious_changes_to_file_associations.yml +++ b/detections/deprecated/suspicious_changes_to_file_associations.yml @@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by Registry.process_id Registry.dest | `drop_dm_object_name("Registry")` | table process_id dest registry_path]| `suspicious_changes_to_file_associations_filter` ' tags: - analytics_story: + analytic_story: - Suspicious Windows Registry Activities - Windows File Extension and Association Abuse asset_type: Endpoint diff --git a/detections/deprecated/suspicious_file_write.yml b/detections/deprecated/suspicious_file_write.yml index 86622fea54..5bee6c513a 100644 --- a/detections/deprecated/suspicious_file_write.yml +++ b/detections/deprecated/suspicious_file_write.yml @@ -25,7 +25,7 @@ search: '| tstats `security_content_summariesonly` count values(Filesystem.actio | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Filesystem)` | `suspicious_writes` | `suspicious_file_write_filter`' tags: - analytics_story: + analytic_story: - Hidden Cobra Malware asset_type: Endpoint cis20: diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/detections/deprecated/suspicious_writes_to_system_volume_information.yml index 3dec2e4869..328c46edda 100644 --- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml +++ b/detections/deprecated/suspicious_writes_to_system_volume_information.yml @@ -16,7 +16,7 @@ search: (`sysmon` OR tag=process) EventCode=11 process_id!=4 file_path=*System\ Image, file_path | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `suspicious_writes_to_system_volume_information_filter` tags: - analytics_story: + analytic_story: - Collection and Staging asset_type: Windows cis20: diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/detections/deprecated/uncommon_processes_on_endpoint.yml index 34721807d9..c2c57b8ffc 100644 --- a/detections/deprecated/uncommon_processes_on_endpoint.yml +++ b/detections/deprecated/uncommon_processes_on_endpoint.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process_name | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` | `uncommon_processes` |`uncommon_processes_on_endpoint_filter` ' tags: - analytics_story: + analytic_story: - Windows Privilege Escalation - Unusual Processes asset_type: Endpoint diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/detections/deprecated/unsigned_image_loaded_by_lsass.yml index c2083e5e5d..de021aa280 100644 --- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml +++ b/detections/deprecated/unsigned_image_loaded_by_lsass.yml @@ -19,7 +19,7 @@ search: '`sysmon` EventID=7 Image=*lsass.exe Signed=false | stats count min(_tim | rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `unsigned_image_loaded_by_lsass_filter` ' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Windows cis20: diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/detections/deprecated/unsuccessful_netbackup_backups.yml index 693fc0b676..340410c62c 100644 --- a/detections/deprecated/unsuccessful_netbackup_backups.yml +++ b/detections/deprecated/unsuccessful_netbackup_backups.yml @@ -15,7 +15,7 @@ search: '`netbackup` | stats latest(_time) as latestTime by COMPUTERNAME, MESSAG | rename COMPUTERNAME as dest, MESSAGE as signature | table latestTime, dest, signature | `unsuccessful_netbackup_backups_filter`' tags: - analytics_story: + analytic_story: - Monitor Backup Solution asset_type: Endpoint cis20: diff --git a/detections/deprecated/windows_connhost_exe_force_flag.yml b/detections/deprecated/windows_connhost_exe_force_flag.yml index 3a5a669a05..f0d89483df 100644 --- a/detections/deprecated/windows_connhost_exe_force_flag.yml +++ b/detections/deprecated/windows_connhost_exe_force_flag.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `windows_connhost_exe_started_forcefully_filter`' tags: - analytics_story: + analytic_story: - Ryuk Ransomware asset_type: Endpoint cis20: diff --git a/detections/deprecated/windows_disableantispyware_reg.yml b/detections/deprecated/windows_disableantispyware_reg.yml index 9cef0953b5..c7a25f3b91 100644 --- a/detections/deprecated/windows_disableantispyware_reg.yml +++ b/detections/deprecated/windows_disableantispyware_reg.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Registry.registry_path Registry.registry_value_name | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `windows_disableantispyware_registry_filter`' tags: - analytics_story: + analytic_story: - Ryuk Ransomware asset_type: Endpoint cis20: diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/detections/deprecated/windows_hosts_file_modification.yml index f4e8c3dfc8..eadeb4c2b1 100644 --- a/detections/deprecated/windows_hosts_file_modification.yml +++ b/detections/deprecated/windows_hosts_file_modification.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | search Filesystem.file_name=hosts AND Filesystem.file_path=*Windows\\System32\\* | `drop_dm_object_name(Filesystem)` | `windows_hosts_file_modification_filter`' tags: - analytics_story: + analytic_story: - Host Redirection asset_type: Endpoint cis20: diff --git a/detections/endpoint/access_lsass_memory_for_dump_creation.yml b/detections/endpoint/access_lsass_memory_for_dump_creation.yml index 442b804b09..eb7bc16342 100644 --- a/detections/endpoint/access_lsass_memory_for_dump_creation.yml +++ b/detections/endpoint/access_lsass_memory_for_dump_creation.yml @@ -18,7 +18,7 @@ search: '`sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* OR TargetProcessId, SourceImage, SourceProcessId | rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `access_lsass_memory_for_dump_creation_filter` ' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Windows automated_detection_testing: passed diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 546f646420..6060c1b1f6 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.user | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `attempt_to_add_certificate_to_untrusted_store_filter`' tags: - analytics_story: + analytic_story: - Disabling Security Tools asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml b/detections/endpoint/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml index a5c43325e6..a0f2a3a3ae 100644 --- a/detections/endpoint/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml +++ b/detections/endpoint/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Registry.registry_value_name Registry.dest | `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | `attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass_filter`' tags: - analytics_story: + analytic_story: - Malicious PowerShell - Credential Dumping asset_type: Endpoint diff --git a/detections/endpoint/attempt_to_stop_security_service.yml b/detections/endpoint/attempt_to_stop_security_service.yml index 57cb55bb92..6cbda381e3 100644 --- a/detections/endpoint/attempt_to_stop_security_service.yml +++ b/detections/endpoint/attempt_to_stop_security_service.yml @@ -25,7 +25,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as |lookup security_services_lookup service as process OUTPUTNEW category, description | search category=security | `attempt_to_stop_security_service_filter`' tags: - analytics_story: + analytic_story: - Disabling Security Tools asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml index 576e0884cd..a52930f64e 100644 --- a/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/attempted_credential_dump_from_registry_via_reg_exe.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by Processes.user Processes.process_name Processes.process Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter`' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/batch_file_write_to_system32.yml b/detections/endpoint/batch_file_write_to_system32.yml index 18dc633877..cd96de645d 100644 --- a/detections/endpoint/batch_file_write_to_system32.yml +++ b/detections/endpoint/batch_file_write_to_system32.yml @@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime rex field=file_name "(?\.[^\.]+)$" | search file_path=*system32* AND file_extension=.bat | `batch_file_write_to_system32_filter`' tags: - analytics_story: + analytic_story: - SamSam Ransomware asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/bcdedit_failure_recovery_modification.yml b/detections/endpoint/bcdedit_failure_recovery_modification.yml index 0ae1b31cc1..2f458fdd69 100644 --- a/detections/endpoint/bcdedit_failure_recovery_modification.yml +++ b/detections/endpoint/bcdedit_failure_recovery_modification.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `bcdedit_failure_recovery_modification_filter`' tags: - analytics_story: + analytic_story: - Ryuk Ransomware - Ransomware asset_type: Endpoint diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index e3054ec328..a42a56d7a1 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -32,7 +32,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`| rex field=file_name "(?\.[^\.]+)$" | `ransomware_extensions` | `common_ransomware_extensions_filter`' tags: - analytics_story: + analytic_story: - SamSam Ransomware - Ryuk Ransonware - Ransomware diff --git a/detections/endpoint/common_ransomware_notes.yml b/detections/endpoint/common_ransomware_notes.yml index bbb933793c..e9124dea55 100644 --- a/detections/endpoint/common_ransomware_notes.yml +++ b/detections/endpoint/common_ransomware_notes.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `ransomware_notes` | `common_ransomware_notes_filter`' tags: - analytics_story: + analytic_story: - SamSam Ransomware - Ransomware - Ryuk Ransomware diff --git a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml index 84cd19606a..af467e48f5 100644 --- a/detections/endpoint/create_local_admin_accounts_using_net_exe.yml +++ b/detections/endpoint/create_local_admin_accounts_using_net_exe.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.user) | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`create_local_admin_accounts_using_net_exe_filter` ' tags: - analytics_story: + analytic_story: - DHS Report TA18-074A asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml index b95aa3fae8..9f161d1cd3 100644 --- a/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml +++ b/detections/endpoint/create_or_delete_windows_shares_using_net_exe.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.user) Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | search process=*share* | `create_or_delete_windows_shares_using_net_exe_filter` ' tags: - analytics_story: + analytic_story: - Hidden Cobra Malware asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/create_remote_thread_into_lsass.yml b/detections/endpoint/create_remote_thread_into_lsass.yml index 24aa9ae850..b63dab014d 100644 --- a/detections/endpoint/create_remote_thread_into_lsass.yml +++ b/detections/endpoint/create_remote_thread_into_lsass.yml @@ -18,7 +18,7 @@ search: '`sysmon` EventID=8 TargetImage=*lsass.exe | stats count min(_time) as f Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `create_remote_thread_into_lsass_filter`' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Windows automated_detection_testing: passed diff --git a/detections/endpoint/creation_of_shadow_copy.yml b/detections/endpoint/creation_of_shadow_copy.yml index 8b93d6f519..ce903eba82 100644 --- a/detections/endpoint/creation_of_shadow_copy.yml +++ b/detections/endpoint/creation_of_shadow_copy.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `creation_of_shadow_copy_filter`' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml index 517d3cc923..dc0a05d2a5 100644 --- a/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml +++ b/detections/endpoint/creation_of_shadow_copy_with_wmic_and_powershell.yml @@ -13,7 +13,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by Processes.user Processes.process_name Processes.process Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `creation_of_shadow_copy_with_wmic_and_powershell_filter`' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml index 70342ff50c..e827ca844e 100644 --- a/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_copy_command_from_shadow_copy.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `credential_dumping_via_copy_command_from_shadow_copy_filter` ' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml index 50d148998c..7e5e824653 100644 --- a/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml +++ b/detections/endpoint/credential_dumping_via_symlink_to_shadow_copy.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `credential_dumping_via_symlink_to_shadow_copy_filter` ' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index 9d55c62282..c6e896086c 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `deleting_shadow_copies_filter`' tags: - analytics_story: + analytic_story: - Windows Log Manipulation - SamSam Ransomware - Ransomware diff --git a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml index f7bf9541e6..f420602358 100644 --- a/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/endpoint/detect_activity_related_to_pass_the_hash_attacks.yml @@ -15,7 +15,7 @@ search: '`wineventlog_security` EventCode=4624 (Logon_Type=3 Logon_Process=NtLmS as lastTime by EventCode, Logon_Type, WorkstationName, user, dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_activity_related_to_pass_the_hash_attacks_filter` ' tags: - analytics_story: + analytic_story: - Lateral Movement asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/detect_computer_changed_with_anonymous_account.yml b/detections/endpoint/detect_computer_changed_with_anonymous_account.yml index 37c7440569..844e986ff4 100644 --- a/detections/endpoint/detect_computer_changed_with_anonymous_account.yml +++ b/detections/endpoint/detect_computer_changed_with_anonymous_account.yml @@ -17,7 +17,7 @@ search: '`wineventlog_security` EventCode=4624 OR EventCode=4742 TargetUserName= LOGON" LogonType=3 | stats count values(host) as host, values(TargetDomainName) as Domain, values(user) as user | `detect_computer_changed_with_anonymous_account_filter`' tags: - analytics_story: + analytic_story: - Detect Zerologon Attack asset_type: Windows cis20: diff --git a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml index 50572cc0c0..e8e4b7b8e9 100644 --- a/detections/endpoint/detect_credential_dumping_through_lsass_access.yml +++ b/detections/endpoint/detect_credential_dumping_through_lsass_access.yml @@ -21,7 +21,7 @@ search: '`sysmon` EventCode=10 TargetImage=*lsass.exe (GrantedAccess=0x1010 OR G Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_credential_dumping_through_lsass_access_filter` ' tags: - analytics_story: + analytic_story: - Credential Dumping - Detect Zerologon Attack asset_type: Windows diff --git a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml index a63c0934ae..f59b709091 100644 --- a/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml +++ b/detections/endpoint/detect_excessive_account_lockouts_from_endpoint.yml @@ -27,7 +27,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search count > 5 | `detect_excessive_account_lockouts_from_endpoint_filter`' tags: - analytics_story: + analytic_story: - Account Monitoring and Controls asset_type: Windows automated_detection_testing: passed diff --git a/detections/endpoint/detect_excessive_user_account_lockouts.yml b/detections/endpoint/detect_excessive_user_account_lockouts.yml index be4bf11e85..b3c2e44e95 100644 --- a/detections/endpoint/detect_excessive_user_account_lockouts.yml +++ b/detections/endpoint/detect_excessive_user_account_lockouts.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime |`drop_dm_object_name("Account_Management")`| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search count > 5 | `detect_excessive_user_account_lockouts_filter`' tags: - analytics_story: + analytic_story: - Account Monitoring and Controls asset_type: Windows automated_detection_testing: passed diff --git a/detections/endpoint/detect_mshta_inline_hta_execution.yml b/detections/endpoint/detect_mshta_inline_hta_execution.yml index 0b6a053288..51f340892b 100644 --- a/detections/endpoint/detect_mshta_inline_hta_execution.yml +++ b/detections/endpoint/detect_mshta_inline_hta_execution.yml @@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_mshta_inline_hta_execution_filter`' tags: - analytics_story: + analytic_story: - Suspicious MSHTA Activity asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/detect_mshta_renamed.yml b/detections/endpoint/detect_mshta_renamed.yml index f2c56ea04c..0221334b4b 100644 --- a/detections/endpoint/detect_mshta_renamed.yml +++ b/detections/endpoint/detect_mshta_renamed.yml @@ -22,7 +22,7 @@ search: '`sysmon` EventID=1 (OriginalFileName=mshta.exe AND process_name!=mshta. rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `detect_mshta_renamed_filter`' tags: - analytics_story: + analytic_story: - Suspicious MSHTA Activity asset_type: Endpoint cis20: diff --git a/detections/endpoint/detect_mshta_url_in_command_line.yml b/detections/endpoint/detect_mshta_url_in_command_line.yml index ab60cb1989..5b58205fe8 100644 --- a/detections/endpoint/detect_mshta_url_in_command_line.yml +++ b/detections/endpoint/detect_mshta_url_in_command_line.yml @@ -25,7 +25,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.process_name Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_mshta_url_in_command_line_filter`' tags: - analytics_story: + analytic_story: - Suspicious MSHTA Activity asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/detect_new_local_admin_account.yml b/detections/endpoint/detect_new_local_admin_account.yml index fa2b9b8a1d..10f088bea5 100644 --- a/detections/endpoint/detect_new_local_admin_account.yml +++ b/detections/endpoint/detect_new_local_admin_account.yml @@ -14,7 +14,7 @@ search: '`wineventlog_security` EventCode=4720 OR (EventCode=4732 Group_Name=Adm | stats count min(_time) as firstTime max(_time) as lastTime by user dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_new_local_admin_account_filter`' tags: - analytics_story: + analytic_story: - DHS Report TA18-074A asset_type: Windows automated_detection_testing: passed diff --git a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml index edfb52a551..5b9e1c2b55 100644 --- a/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml +++ b/detections/endpoint/detect_path_interception_by_creation_of_program_exe.yml @@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime where process_name != service_process | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_path_interception_by_creation_of_program_exe_filter`' tags: - analytics_story: + analytic_story: - Windows Persistence Techniques asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml index 2f6125666a..2be2e9fa47 100644 --- a/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml +++ b/detections/endpoint/detect_processes_used_for_system_network_configuration_discovery.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces | transaction dest connected=false maxpause=5m |where eventcount>=5 | table firstTime lastTime dest user process_name process parent_process eventcount | `detect_processes_used_for_system_network_configuration_discovery_filter`' tags: - analytics_story: + analytic_story: - Unusual Processes asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml index 98902652c2..2ca354306e 100644 --- a/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml +++ b/detections/endpoint/detect_prohibited_applications_spawning_cmd_exe.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.dest Processes.user| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |search [`prohibited_apps_launching_cmd`] | `detect_prohibited_applications_spawning_cmd_exe_filter`' tags: - analytics_story: + analytic_story: - Suspicious Command-Line Executions - Suspicious MSHTA Activity - Suspicious Zoom Child Processes diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index c6a7ef17f7..d375dc3c1a 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.dest Processes.parent_process_name | `drop_dm_object_name(Processes)`| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_psexec_with_accepteula_flag_filter`' tags: - analytics_story: + analytic_story: - SamSam Ransomware - DHS Report TA18-074A asset_type: Endpoint diff --git a/detections/endpoint/detect_rare_executables.yml b/detections/endpoint/detect_rare_executables.yml index 254b752f84..affb6511ca 100644 --- a/detections/endpoint/detect_rare_executables.yml +++ b/detections/endpoint/detect_rare_executables.yml @@ -25,7 +25,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.dest) by Processes.process_name | rare Processes.process_name limit=30 | rename Processes.process_name as process| `filter_rare_process_allow_list`| table process ] | `detect_rare_executables_filter` ' tags: - analytics_story: + analytic_story: - 'Emotet Malware DHS Report TA18-201A ' - Unusual Processes asset_type: Endpoint diff --git a/detections/endpoint/detect_rundll32_inline_hta_execution.yml b/detections/endpoint/detect_rundll32_inline_hta_execution.yml index 66bb9686e5..f5459866ee 100644 --- a/detections/endpoint/detect_rundll32_inline_hta_execution.yml +++ b/detections/endpoint/detect_rundll32_inline_hta_execution.yml @@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_rundll32_inline_hta_execution_filter`' tags: - analytics_story: + analytic_story: - Suspicious MSHTA Activity asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml index 0d22359061..fc91a0fe0c 100644 --- a/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml +++ b/detections/endpoint/detect_use_of_cmd_exe_to_launch_script_interpreters.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | `detect_use_of_cmd_exe_to_launch_script_interpreters_filter`' tags: - analytics_story: + analytic_story: - 'Emotet Malware DHS Report TA18-201A ' - Suspicious Command-Line Executions asset_type: Endpoint diff --git a/detections/endpoint/disabling_remote_user_account_control.yml b/detections/endpoint/disabling_remote_user_account_control.yml index 55840b3939..4fb6593430 100644 --- a/detections/endpoint/disabling_remote_user_account_control.yml +++ b/detections/endpoint/disabling_remote_user_account_control.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Registry.user Registry.registry_path Registry.registry_value_name Registry.action | `drop_dm_object_name(Registry)` | `disabling_remote_user_account_control_filter`' tags: - analytics_story: + analytic_story: - Windows Defense Evasion Tactics - Suspicious Windows Registry Activities asset_type: Endpoint diff --git a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml index d32084896d..8a3dc3680b 100644 --- a/detections/endpoint/dump_lsass_via_comsvcs_dll.yml +++ b/detections/endpoint/dump_lsass_via_comsvcs_dll.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `dump_lsass_via_comsvcs_dll_filter`' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/execution_of_file_with_multiple_extensions.yml b/detections/endpoint/execution_of_file_with_multiple_extensions.yml index 752b73b336..342f2ccac7 100644 --- a/detections/endpoint/execution_of_file_with_multiple_extensions.yml +++ b/detections/endpoint/execution_of_file_with_multiple_extensions.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.dest Processes.user Processes.process Processes.parent_process | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` | `execution_of_file_with_multiple_extensions_filter`' tags: - analytics_story: + analytic_story: - Windows File Extension and Association Abuse asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/file_with_samsam_extension.yml b/detections/endpoint/file_with_samsam_extension.yml index 57e7a5163e..8b94c6a383 100644 --- a/detections/endpoint/file_with_samsam_extension.yml +++ b/detections/endpoint/file_with_samsam_extension.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime OR file_extension=.berkshire OR file_extension=.satoshi OR file_extension=.sophos OR file_extension=.keyxml | `file_with_samsam_extension_filter`' tags: - analytics_story: + analytic_story: - SamSam Ransomware asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/first_time_seen_child_process_of_zoom.yml b/detections/endpoint/first_time_seen_child_process_of_zoom.yml index 2e97e97247..b8ae1876f6 100644 --- a/detections/endpoint/first_time_seen_child_process_of_zoom.yml +++ b/detections/endpoint/first_time_seen_child_process_of_zoom.yml @@ -27,7 +27,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime value | `security_content_ctime(firstTime)` | table firstTime dest, process_id, process_name, parent_process_id, parent_process_name |`first_time_seen_child_process_of_zoom_filter`' tags: - analytics_story: + analytic_story: - Suspicious Zoom Child Processes asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml index cf98d5e425..563fe74065 100644 --- a/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml +++ b/detections/endpoint/hiding_files_and_directories_with_attrib_exe.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) values(Proce Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| `hiding_files_and_directories_with_attrib_exe_filter` ' tags: - analytics_story: + analytic_story: - Windows Defense Evasion Tactics - Windows Persistence Techniques asset_type: '' diff --git a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml index bb5c5e9e84..733a8d879c 100644 --- a/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml +++ b/detections/endpoint/kerberoasting_spn_request_with_rc4_encryption.yml @@ -16,7 +16,7 @@ search: '`wineventlog_security` EventCode=4769 Ticket_Options=0x40810000 Ticket_ Ticket_Encryption_Type, Ticket_Options | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `kerberoasting_spn_request_with_rc4_encryption_filter`' tags: - analytics_story: + analytic_story: - Lateral Movement asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml index b6b28a3bd2..f3b3419074 100644 --- a/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/malicious_powershell_process___connect_to_internet_with_hidden_window.yml @@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `malicious_powershell_process___connect_to_internet_with_hidden_window_filter`' tags: - analytics_story: + analytic_story: - Malicious PowerShell - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns asset_type: Endpoint diff --git a/detections/endpoint/malicious_powershell_process___encoded_command.yml b/detections/endpoint/malicious_powershell_process___encoded_command.yml index a4545cb286..9e8041caed 100644 --- a/detections/endpoint/malicious_powershell_process___encoded_command.yml +++ b/detections/endpoint/malicious_powershell_process___encoded_command.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `malicious_powershell_process___encoded_command_filter`' tags: - analytics_story: + analytic_story: - Malicious PowerShell - Sunburst Malware asset_type: Endpoint diff --git a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml index 10dfcea5e0..08ed4f2961 100644 --- a/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml +++ b/detections/endpoint/malicious_powershell_process___execution_policy_bypass.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process_id) bypass *") by Processes.process_id, Processes.user, Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `malicious_powershell_process___execution_policy_bypass_filter`' tags: - analytics_story: + analytic_story: - DHS Report TA18-074A asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml index b4184a83ca..a3e67723d2 100644 --- a/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml +++ b/detections/endpoint/malicious_powershell_process_with_obfuscation_techniques.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces + (mvcount(split(process, "^"))-1) + (mvcount(split(process, "''"))-1) | `malicious_powershell_process_with_obfuscation_techniques_filter` | search num_obfuscation > 10 ' tags: - analytics_story: + analytic_story: - Malicious PowerShell asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml index 503f3d0a72..bf4f35075a 100644 --- a/detections/endpoint/monitor_registry_keys_for_print_monitors.yml +++ b/detections/endpoint/monitor_registry_keys_for_print_monitors.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_name Registry.action | `drop_dm_object_name(Registry)` | `monitor_registry_keys_for_print_monitors_filter`' tags: - analytics_story: + analytic_story: - Suspicious Windows Registry Activities - Windows Persistence Techniques asset_type: Endpoint diff --git a/detections/endpoint/nltest_domain_trust_discovery.yml b/detections/endpoint/nltest_domain_trust_discovery.yml index b247efc80f..759d43e0bf 100644 --- a/detections/endpoint/nltest_domain_trust_discovery.yml +++ b/detections/endpoint/nltest_domain_trust_discovery.yml @@ -27,7 +27,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `nltest_domain_trust_discovery_filter`' tags: - analytics_story: + analytic_story: - Ryuk Ransomware asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/overwriting_accessibility_binaries.yml b/detections/endpoint/overwriting_accessibility_binaries.yml index 036df21cec..8c2d71c1bf 100644 --- a/detections/endpoint/overwriting_accessibility_binaries.yml +++ b/detections/endpoint/overwriting_accessibility_binaries.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by Filesystem.file_name Filesystem.dest | `drop_dm_object_name(Filesystem)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `overwriting_accessibility_binaries_filter`' tags: - analytics_story: + analytic_story: - Windows Privilege Escalation asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml index 0021b434f1..a8db6f3522 100644 --- a/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml +++ b/detections/endpoint/process_creating_lnk_file_in_suspicious_location.yml @@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | table firstTime, lastTime, lnk_pid, process_id, user, dest, file_name, file_path, process_name, process, process_path, file_hash | `process_creating_lnk_file_in_suspicious_location_filter` ' tags: - analytics_story: + analytic_story: - Phishing Payloads asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/process_execution_via_wmi.yml b/detections/endpoint/process_execution_via_wmi.yml index 3de408e98c..d1b43912da 100644 --- a/detections/endpoint/process_execution_via_wmi.yml +++ b/detections/endpoint/process_execution_via_wmi.yml @@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.process_name | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `process_execution_via_wmi_filter` ' tags: - analytics_story: + analytic_story: - Suspicious WMI Use asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/processes_launching_netsh.yml b/detections/endpoint/processes_launching_netsh.yml index 54360e5222..0babe53883 100644 --- a/detections/endpoint/processes_launching_netsh.yml +++ b/detections/endpoint/processes_launching_netsh.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.process_name Processes.user Processes.dest |`drop_dm_object_name("Processes")` |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` |`processes_launching_netsh_filter`' tags: - analytics_story: + analytic_story: - Netsh Abuse - Disabling Security Tools - DHS Report TA18-074A diff --git a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml index 2e462fcb6a..254508329d 100644 --- a/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml +++ b/detections/endpoint/reg_exe_manipulating_windows_services_registry_keys.yml @@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `reg_exe_manipulating_windows_services_registry_keys_filter`' tags: - analytics_story: + analytic_story: - Windows Service Abuse - Windows Persistence Techniques asset_type: Endpoint diff --git a/detections/endpoint/registry_keys_for_creating_shim_databases.yml b/detections/endpoint/registry_keys_for_creating_shim_databases.yml index 0db50962ad..ef74d9e0df 100644 --- a/detections/endpoint/registry_keys_for_creating_shim_databases.yml +++ b/detections/endpoint/registry_keys_for_creating_shim_databases.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count values(Registry.registr by Registry.dest Registry.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `registry_keys_for_creating_shim_databases_filter`' tags: - analytics_story: + analytic_story: - Suspicious Windows Registry Activities - Windows Persistence Techniques asset_type: Endpoint diff --git a/detections/endpoint/registry_keys_used_for_persistence.yml b/detections/endpoint/registry_keys_used_for_persistence.yml index f427b907f7..5717404846 100644 --- a/detections/endpoint/registry_keys_used_for_persistence.yml +++ b/detections/endpoint/registry_keys_used_for_persistence.yml @@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count values(Registry.registr by Registry.dest Registry.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `registry_keys_used_for_persistence_filter`' tags: - analytics_story: + analytic_story: - Suspicious Windows Registry Activities - Suspicious MSHTA Activity - DHS Report TA18-074A diff --git a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml index 24449054c6..0cdb244754 100644 --- a/detections/endpoint/registry_keys_used_for_privilege_escalation.yml +++ b/detections/endpoint/registry_keys_used_for_privilege_escalation.yml @@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTim Registry.registry_key_name | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name(Registry)` | `registry_keys_used_for_privilege_escalation_filter`' tags: - analytics_story: + analytic_story: - Windows Privilege Escalation - Suspicious Windows Registry Activities asset_type: Endpoint diff --git a/detections/endpoint/remote_process_instantiation_via_wmi.yml b/detections/endpoint/remote_process_instantiation_via_wmi.yml index e9f2d7399e..5a2aa04fc0 100644 --- a/detections/endpoint/remote_process_instantiation_via_wmi.yml +++ b/detections/endpoint/remote_process_instantiation_via_wmi.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.parent_process_name Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `remote_process_instantiation_via_wmi_filter`' tags: - analytics_story: + analytic_story: - Ransomware - Suspicious WMI Use asset_type: Endpoint diff --git a/detections/endpoint/rundll_loading_dll_by_ordinal.yml b/detections/endpoint/rundll_loading_dll_by_ordinal.yml index d08b0fb243..61047233a0 100644 --- a/detections/endpoint/rundll_loading_dll_by_ordinal.yml +++ b/detections/endpoint/rundll_loading_dll_by_ordinal.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.process Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `rundll_loading_dll_by_ordinal_filter`' tags: - analytics_story: + analytic_story: - Unusual Processes asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/ryuk_test_files_detected.yml b/detections/endpoint/ryuk_test_files_detected.yml index 4fa192140d..452cf9c9a5 100644 --- a/detections/endpoint/ryuk_test_files_detected.yml +++ b/detections/endpoint/ryuk_test_files_detected.yml @@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime BY "Filesystem.dest", "Filesystem.user", "Filesystem.file_path" | `drop_dm_object_name(Filesystem)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `ryuk_test_files_detected_filter`' tags: - analytics_story: + analytic_story: - Ryuk Ransomware asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/samsam_test_file_write.yml b/detections/endpoint/samsam_test_file_write.yml index 8867c2f48a..4a7f607e67 100644 --- a/detections/endpoint/samsam_test_file_write.yml +++ b/detections/endpoint/samsam_test_file_write.yml @@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by Filesystem.file_path | `drop_dm_object_name(Filesystem)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `samsam_test_file_write_filter`' tags: - analytics_story: + analytic_story: - SamSam Ransomware asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/sc_exe_manipulating_windows_services.yml b/detections/endpoint/sc_exe_manipulating_windows_services.yml index 507e36d10f..b723def98b 100644 --- a/detections/endpoint/sc_exe_manipulating_windows_services.yml +++ b/detections/endpoint/sc_exe_manipulating_windows_services.yml @@ -15,7 +15,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `sc_exe_manipulating_windows_services_filter`' tags: - analytics_story: + analytic_story: - Windows Service Abuse - DHS Report TA18-074A - Orangeworm Attack Group diff --git a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml index 61579e5285..4df4038a20 100644 --- a/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml +++ b/detections/endpoint/scheduled_task_deleted_or_created_via_cmd.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `scheduled_task_deleted_or_created_via_cmd_filter` ' tags: - analytics_story: + analytic_story: - DHS Report TA18-074A - Sunburst Malware asset_type: Endpoint diff --git a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml index 759639bdc1..918cac5c66 100644 --- a/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml +++ b/detections/endpoint/schtasks_scheduling_job_on_remote_system.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schtasks_scheduling_job_on_remote_system_filter`' tags: - analytics_story: + analytic_story: - Lateral Movement - Sunburst Malware asset_type: Endpoint diff --git a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml index 208beac3dd..c8b8603bc8 100644 --- a/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml +++ b/detections/endpoint/schtasks_used_for_forcing_a_reboot.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `schtasks_used_for_forcing_a_reboot_filter`' tags: - analytics_story: + analytic_story: - Windows Persistence Techniques - Ransomware asset_type: Endpoint diff --git a/detections/endpoint/script_execution_via_wmi.yml b/detections/endpoint/script_execution_via_wmi.yml index 7ca598110c..431b251dcf 100644 --- a/detections/endpoint/script_execution_via_wmi.yml +++ b/detections/endpoint/script_execution_via_wmi.yml @@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `script_execution_via_wmi_filter` ' tags: - analytics_story: + analytic_story: - Suspicious WMI Use asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/shim_database_file_creation.yml b/detections/endpoint/shim_database_file_creation.yml index 7567428139..754350edd5 100644 --- a/detections/endpoint/shim_database_file_creation.yml +++ b/detections/endpoint/shim_database_file_creation.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count values(Filesystem.actio by Filesystem.file_name Filesystem.dest | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` |`drop_dm_object_name(Filesystem)` | `shim_database_file_creation_filter`' tags: - analytics_story: + analytic_story: - Windows Persistence Techniques asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml index 0ec9e2f3da..02f8b61983 100644 --- a/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml +++ b/detections/endpoint/shim_database_installation_with_suspicious_parameters.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as Processes.dest Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter`' tags: - analytics_story: + analytic_story: - Windows Persistence Techniques asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/short_lived_windows_accounts.yml b/detections/endpoint/short_lived_windows_accounts.yml index 3755d3848a..d78611ebe3 100644 --- a/detections/endpoint/short_lived_windows_accounts.yml +++ b/detections/endpoint/short_lived_windows_accounts.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` values(All_Changes.result_id) | transaction user connected=false maxspan=240m | table firstTime lastTime count user dest result_id | `short_lived_windows_accounts_filter`' tags: - analytics_story: + analytic_story: - Account Monitoring and Controls asset_type: Windows automated_detection_testing: passed diff --git a/detections/endpoint/single_letter_process_on_endpoint.yml b/detections/endpoint/single_letter_process_on_endpoint.yml index d1b3490b24..2135f0cf98 100644 --- a/detections/endpoint/single_letter_process_on_endpoint.yml +++ b/detections/endpoint/single_letter_process_on_endpoint.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime AND endExe=1 | table count, firstTime, lastTime, dest, user, process, process_name | `single_letter_process_on_endpoint_filter`' tags: - analytics_story: + analytic_story: - DHS Report TA18-074A asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml b/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml index afc6c869c2..6c50bcbd39 100644 --- a/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml +++ b/detections/endpoint/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml @@ -22,7 +22,7 @@ search: ' | from read_ssa_enriched_events() | eval timestamp=parse_long(ucast(ma ) | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" | into write_ssa_detected_events(); ' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Endpoint cis20: diff --git a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml index f0e3ee51c7..9d8da984c2 100644 --- a/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml +++ b/detections/endpoint/ssa___detect_dump_lsass_memory_using_comsvcs.yml @@ -20,7 +20,7 @@ search: '| from read_ssa_enriched_events() | eval tenant=ucast(map_get(input_eve | eval start_time = timestamp, end_time = timestamp, entities = mvappend(machine), body = "TBD" | into write_ssa_detected_events();' tags: - analytics_story: + analytic_story: - Credential Dumping asset_type: Endpoint cis20: diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml index a052406fc5..8f770d977b 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_rename.yml @@ -23,7 +23,7 @@ search: '`sysmon` EventID=1 (OriginalFileName=microsoft.workflow.compiler.exe OR rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `suspicious_microsoft_workflow_compiler_rename_filter`' tags: - analytics_story: + analytic_story: - Trusted Developer Utilities Proxy Execution asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml index a237251a0e..2958264a27 100644 --- a/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml +++ b/detections/endpoint/suspicious_microsoft_workflow_compiler_usage.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces by Processes.dest Processes.parent_process Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_microsoft_workflow_compiler_usage_filter`' tags: - analytics_story: + analytic_story: - Trusted Developer Utilities Proxy Execution asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_msbuild_path.yml b/detections/endpoint/suspicious_msbuild_path.yml index d73648cfbc..5e70da6104 100644 --- a/detections/endpoint/suspicious_msbuild_path.yml +++ b/detections/endpoint/suspicious_msbuild_path.yml @@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.parent_process Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `suspicious_msbuild_path_filter`' tags: - analytics_story: + analytic_story: - Trusted Developer Utilities Proxy Execution MSBuild asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_msbuild_rename.yml b/detections/endpoint/suspicious_msbuild_rename.yml index 24aa58b8f2..27af9723dd 100644 --- a/detections/endpoint/suspicious_msbuild_rename.yml +++ b/detections/endpoint/suspicious_msbuild_rename.yml @@ -22,7 +22,7 @@ search: '`sysmon` EventID=1 (OriginalFileName=msbuild.exe OR process_name=msbuil rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `suspicious_msbuild_rename_filter`' tags: - analytics_story: + analytic_story: - Trusted Developer Utilities Proxy Execution MSBuild asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_msbuild_spawn.yml b/detections/endpoint/suspicious_msbuild_spawn.yml index 4b5fededa6..bea0086cb9 100644 --- a/detections/endpoint/suspicious_msbuild_spawn.yml +++ b/detections/endpoint/suspicious_msbuild_spawn.yml @@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_msbuild_spawn_filter`' tags: - analytics_story: + analytic_story: - Trusted Developer Utilities Proxy Execution MSBuild asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_mshta_child_process.yml b/detections/endpoint/suspicious_mshta_child_process.yml index fadc046961..47f83a0198 100644 --- a/detections/endpoint/suspicious_mshta_child_process.yml +++ b/detections/endpoint/suspicious_mshta_child_process.yml @@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_mshta_child_process_filter`' tags: - analytics_story: + analytic_story: - Suspicious MSHTA Activity asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_mshta_spawn.yml b/detections/endpoint/suspicious_mshta_spawn.yml index 8ac3bd9375..22de98ef5f 100644 --- a/detections/endpoint/suspicious_mshta_spawn.yml +++ b/detections/endpoint/suspicious_mshta_spawn.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces by Processes.dest Processes.parent_process Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_mshta_spawn_filter`' tags: - analytics_story: + analytic_story: - Suspicious MSHTA Activity asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/suspicious_reg_exe_process.yml b/detections/endpoint/suspicious_reg_exe_process.yml index cad5927a5d..1417a47c4c 100644 --- a/detections/endpoint/suspicious_reg_exe_process.yml +++ b/detections/endpoint/suspicious_reg_exe_process.yml @@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `security_content_ctime(lastTime)` | rename parent_process_id as process_id |dedup process_id| table process_id dest] | `suspicious_reg_exe_process_filter` ' tags: - analytics_story: + analytic_story: - Windows Defense Evasion Tactics - Disabling Security Tools - DHS Report TA18-074A diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index 33f738ca21..ad1268e084 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `suspicious_wevtutil_usage_filter`' tags: - analytics_story: + analytic_story: - Windows Log Manipulation - Ransomware asset_type: '' diff --git a/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml b/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml index 5ed7947224..84ed04e895 100644 --- a/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml +++ b/detections/endpoint/suspicious_writes_to_windows_recycle_bin.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime != "explorer.exe" by Processes.process_id Processes.dest| `drop_dm_object_name("Processes")` | table process_id dest] | `suspicious_writes_to_windows_recycle_bin_filter`' tags: - analytics_story: + analytic_story: - Collection and Staging asset_type: Windows automated_detection_testing: passed diff --git a/detections/endpoint/system_information_discovery_detection.yml b/detections/endpoint/system_information_discovery_detection.yml index 411482d0c3..1e88beec0b 100644 --- a/detections/endpoint/system_information_discovery_detection.yml +++ b/detections/endpoint/system_information_discovery_detection.yml @@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by user, dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `system_information_discovery_detection_filter`' tags: - analytics_story: + analytic_story: - Discovery Techniques asset_type: Windows automated_detection_testing: passed diff --git a/detections/endpoint/system_processes_run_from_unexpected_locations.yml b/detections/endpoint/system_processes_run_from_unexpected_locations.yml index 2e11cc2ecf..075da9711f 100644 --- a/detections/endpoint/system_processes_run_from_unexpected_locations.yml +++ b/detections/endpoint/system_processes_run_from_unexpected_locations.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process_hash| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `is_windows_system_file` | `system_processes_run_from_unexpected_locations_filter`' tags: - analytics_story: + analytic_story: - Suspicious Command-Line Executions - Unusual Processes - Ransomware diff --git a/detections/endpoint/unload_sysmon_filter_driver.yml b/detections/endpoint/unload_sysmon_filter_driver.yml index 75dced5aff..5b00bbd265 100644 --- a/detections/endpoint/unload_sysmon_filter_driver.yml +++ b/detections/endpoint/unload_sysmon_filter_driver.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime |`unload_sysmon_filter_driver_filter`| table firstTime lastTime dest user count process_name process_id parent_process_name process' tags: - analytics_story: + analytic_story: - Disabling Security Tools asset_type: '' automated_detection_testing: passed diff --git a/detections/endpoint/unusually_long_command_line.yml b/detections/endpoint/unusually_long_command_line.yml index 9fd3de8bc1..841ebbfaa6 100644 --- a/detections/endpoint/unusually_long_command_line.yml +++ b/detections/endpoint/unusually_long_command_line.yml @@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `unusually_long_command_line_filter` |eval threshold = 3 | where maxlen > ((threshold*stdevperhost) + avgperhost)' tags: - analytics_story: + analytic_story: - Suspicious Command-Line Executions - Unusual Processes - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns diff --git a/detections/endpoint/unusually_long_command_line___mltk.yml b/detections/endpoint/unusually_long_command_line___mltk.yml index c4cb475421..c1809c1f3e 100644 --- a/detections/endpoint/unusually_long_command_line___mltk.yml +++ b/detections/endpoint/unusually_long_command_line___mltk.yml @@ -32,7 +32,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | search isOutlier > 0 | table firstTime lastTime user dest process_name process processlen count | `unusually_long_command_line___mltk_filter`' tags: - analytics_story: + analytic_story: - Suspicious Command-Line Executions - Unusual Processes - Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns diff --git a/detections/endpoint/usn_journal_deletion.yml b/detections/endpoint/usn_journal_deletion.yml index d5963ed6ff..0b52b36cd0 100644 --- a/detections/endpoint/usn_journal_deletion.yml +++ b/detections/endpoint/usn_journal_deletion.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | search process="*deletejournal*" AND process="*usn*" | `usn_journal_deletion_filter`' tags: - analytics_story: + analytic_story: - Windows Log Manipulation - Ransomware asset_type: Endpoint diff --git a/detections/endpoint/wbadmin_delete_system_backups.yml b/detections/endpoint/wbadmin_delete_system_backups.yml index 4c5bb06777..6c14df3f16 100644 --- a/detections/endpoint/wbadmin_delete_system_backups.yml +++ b/detections/endpoint/wbadmin_delete_system_backups.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `wbadmin_delete_system_backups_filter`' tags: - analytics_story: + analytic_story: - Ryuk Ransomware - Ransomware asset_type: Endpoint diff --git a/detections/endpoint/windows_adfind_exe.yml b/detections/endpoint/windows_adfind_exe.yml index 3f4c71b6ee..5dd2eaf50c 100644 --- a/detections/endpoint/windows_adfind_exe.yml +++ b/detections/endpoint/windows_adfind_exe.yml @@ -24,7 +24,7 @@ search: ' | tstats `security_content_summariesonly` count min(_time) as firstTim | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_adfind_exe_filter` ' tags: - analytics_story: + analytic_story: - Sunburst Malware asset_type: Endpoint cis20: diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml index 5813b6f446..ea14a4af55 100644 --- a/detections/endpoint/windows_event_log_cleared.yml +++ b/detections/endpoint/windows_event_log_cleared.yml @@ -14,7 +14,7 @@ search: (`wineventlog_security` (EventCode=1102 OR EventCode=1100)) OR (`wineven dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_event_log_cleared_filter` tags: - analytics_story: + analytic_story: - Windows Log Manipulation - Ransomware asset_type: Endpoint diff --git a/detections/endpoint/windows_security_account_manager_stopped.yml b/detections/endpoint/windows_security_account_manager_stopped.yml index 4ebf7b2378..e23063bfc3 100644 --- a/detections/endpoint/windows_security_account_manager_stopped.yml +++ b/detections/endpoint/windows_security_account_manager_stopped.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `drop_dm_object_name(Processes)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `windows_security_account_manager_stopped_filter`' tags: - analytics_story: + analytic_story: - Ryuk Ransomware asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml index 52249d762c..5a4c93c0e5 100644 --- a/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml +++ b/detections/endpoint/wmi_permanent_event_subscription___sysmon.yml @@ -13,7 +13,7 @@ references: [] search: '`sysmon` EventCode=21 | rename host as dest | table _time, dest, user, Operation, EventType, Query, Consumer, Filter | `wmi_permanent_event_subscription___sysmon_filter`' tags: - analytics_story: + analytic_story: - Suspicious WMI Use asset_type: Endpoint automated_detection_testing: passed diff --git a/detections/experimental/application/detect_new_login_attempts_to_routers.yml b/detections/experimental/application/detect_new_login_attempts_to_routers.yml index 6b7e2fa92c..5e25730449 100644 --- a/detections/experimental/application/detect_new_login_attempts_to_routers.yml +++ b/detections/experimental/application/detect_new_login_attempts_to_routers.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count earliest(_time) as earl "-30d@d"), 1, 0) | where isOutlier=1| `security_content_ctime(earliest)`| `security_content_ctime(latest)` | `drop_dm_object_name("Authentication")` | `detect_new_login_attempts_to_routers_filter`' tags: - analytics_story: + analytic_story: - Router and Infrastructure Security asset_type: Endpoint cis20: diff --git a/detections/experimental/application/email_attachments_with_lots_of_spaces.yml b/detections/experimental/application/email_attachments_with_lots_of_spaces.yml index 20502d5345..ba779ee687 100644 --- a/detections/experimental/application/email_attachments_with_lots_of_spaces.yml +++ b/detections/experimental/application/email_attachments_with_lots_of_spaces.yml @@ -26,7 +26,7 @@ search: '| tstats `security_content_summariesonly` count values(All_Email.recipi | eval space_ratio = (mvcount(split(file_name," "))-1)/len(file_name) | search space_ratio >= 0.1 | rex field=recipient_address "(?.*)@" | `email_attachments_with_lots_of_spaces_filter`' tags: - analytics_story: + analytic_story: - 'Emotet Malware DHS Report TA18-201A ' - Suspicious Emails asset_type: Endpoint diff --git a/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml b/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml index 13d8d15280..052b0604bd 100644 --- a/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml +++ b/detections/experimental/application/email_servers_sending_high_volume_traffic_to_hosts.yml @@ -31,7 +31,7 @@ search: '| tstats `security_content_summariesonly` sum(All_Traffic.bytes_out) as 2) | table dest_ip, _time, bytes_out, avg_bytes_out, per_source_avg_bytes_out, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average | `email_servers_sending_high_volume_traffic_to_hosts_filter`' tags: - analytics_story: + analytic_story: - Collection and Staging asset_type: Endpoint cis20: diff --git a/detections/experimental/application/monitor_email_for_brand_abuse.yml b/detections/experimental/application/monitor_email_for_brand_abuse.yml index 7a881838ae..7e57057de7 100644 --- a/detections/experimental/application/monitor_email_for_brand_abuse.yml +++ b/detections/experimental/application/monitor_email_for_brand_abuse.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` values(All_Email.recipient) a brandMonitoring_lookup domain as email_domain OUTPUT domain_abuse | search domain_abuse=true | table message_id, src_user, email_domain, recipients, firstTime, lastTime | `monitor_email_for_brand_abuse_filter`' tags: - analytics_story: + analytic_story: - Brand Monitoring - Suspicious Emails asset_type: Endpoint diff --git a/detections/experimental/application/no_windows_updates_in_a_time_frame.yml b/detections/experimental/application/no_windows_updates_in_a_time_frame.yml index 59c2c5e7d9..1191bb81ad 100644 --- a/detections/experimental/application/no_windows_updates_in_a_time_frame.yml +++ b/detections/experimental/application/no_windows_updates_in_a_time_frame.yml @@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` max(_time) as lastTime from d search isOutlier=1 | rename lastTime as "Last Update Time", | table Host, "Update Status", Product, "Last Update Time" | `no_windows_updates_in_a_time_frame_filter`' tags: - analytics_story: + analytic_story: - Monitor for Updates asset_type: Endpoint cis20: diff --git a/detections/experimental/application/spectre_and_meltdown_vulnerable_systems.yml b/detections/experimental/application/spectre_and_meltdown_vulnerable_systems.yml index f4c5a1fd74..e5be88cd97 100644 --- a/detections/experimental/application/spectre_and_meltdown_vulnerable_systems.yml +++ b/detections/experimental/application/spectre_and_meltdown_vulnerable_systems.yml @@ -15,7 +15,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_ by Vulnerabilities.dest | `drop_dm_object_name(Vulnerabilities)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `spectre_and_meltdown_vulnerable_systems_filter`' tags: - analytics_story: + analytic_story: - Spectre And Meltdown Vulnerabilities asset_type: Endpoint cis20: diff --git a/detections/experimental/application/suspicious_email___uba_anomaly.yml b/detections/experimental/application/suspicious_email___uba_anomaly.yml index 45c42a2ee4..96939d20fb 100644 --- a/detections/experimental/application/suspicious_email___uba_anomaly.yml +++ b/detections/experimental/application/suspicious_email___uba_anomaly.yml @@ -21,7 +21,7 @@ search: '|tstats `security_content_summariesonly` count min(_time) as firstTime | `drop_dm_object_name(UEBA_Anomalies)`| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `suspicious_email___uba_anomaly_filter`' tags: - analytics_story: + analytic_story: - Suspicious Emails asset_type: Endpoint cis20: diff --git a/detections/experimental/application/suspicious_email_attachment_extensions.yml b/detections/experimental/application/suspicious_email_attachment_extensions.yml index 66e4c5e2a0..0b5202b8c5 100644 --- a/detections/experimental/application/suspicious_email_attachment_extensions.yml +++ b/detections/experimental/application/suspicious_email_attachment_extensions.yml @@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime `security_content_ctime(lastTime)` | `drop_dm_object_name("All_Email")` | `suspicious_email_attachments` | `suspicious_email_attachment_extensions_filter` ' tags: - analytics_story: + analytic_story: - 'Emotet Malware DHS Report TA18-201A ' - Suspicious Emails asset_type: Endpoint diff --git a/detections/experimental/application/suspicious_java_classes.yml b/detections/experimental/application/suspicious_java_classes.yml index 4a8c7e6d0f..af40707f7c 100644 --- a/detections/experimental/application/suspicious_java_classes.yml +++ b/detections/experimental/application/suspicious_java_classes.yml @@ -16,7 +16,7 @@ search: '`stream_http` http_method=POST http_content_length>1 | regex form_data= as http_user_agent by src, dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_java_classes_filter`' tags: - analytics_story: + analytic_story: - Apache Struts Vulnerability asset_type: Endpoint cis20: diff --git a/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml b/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml index 8bf7b260a5..28bd134bb1 100644 --- a/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml +++ b/detections/experimental/cloud/amazon_eks_kubernetes_cluster_scan_detection.yml @@ -17,7 +17,7 @@ search: '`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" userAgent!= by src_ip user.username user.groups{} | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` |`amazon_eks_kubernetes_cluster_scan_detection_filter` ' tags: - analytics_story: + analytic_story: - Kubernetes Scanning Activity asset_type: Amazon EKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml b/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml index 2169bc5471..fb23111273 100644 --- a/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml +++ b/detections/experimental/cloud/amazon_eks_kubernetes_pod_scan_detection.yml @@ -18,7 +18,7 @@ search: '`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" verb=list o src_ip cluster_name user.username user.groups{} | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `amazon_eks_kubernetes_pod_scan_detection_filter` ' tags: - analytics_story: + analytic_story: - Kubernetes Scanning Activity asset_type: Amazon EKS Kubernetes cluster Pod kill_chain_phases: diff --git a/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml b/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml index 97e54f034d..8834fff93b 100644 --- a/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml +++ b/detections/experimental/cloud/aws_detect_attach_to_role_policy.yml @@ -16,7 +16,7 @@ search: '`aws_cloudwatchlogs_eks` attach policy| spath requestParameters.policyA eventName errorCode errorMessage status action requestParameters.policyArn userIdentity.sessionContext.attributes.mfaAuthenticated userIdentity.sessionContext.attributes.creationDate | `aws_detect_attach_to_role_policy_filter`' tags: - analytics_story: + analytic_story: - AWS Cross Account Activity asset_type: AWS Account kill_chain_phases: diff --git a/detections/experimental/cloud/aws_detect_permanent_key_creation.yml b/detections/experimental/cloud/aws_detect_permanent_key_creation.yml index c57e1c1eca..ee51203950 100644 --- a/detections/experimental/cloud/aws_detect_permanent_key_creation.yml +++ b/detections/experimental/cloud/aws_detect_permanent_key_creation.yml @@ -15,7 +15,7 @@ search: '`aws_cloudwatchlogs_eks` CreateAccessKey | spath eventName | search eve action status responseElements.accessKey.createDate responseElements.accessKey.status responseElements.accessKey.accessKeyId |`aws_detect_permanent_key_creation_filter`' tags: - analytics_story: + analytic_story: - AWS Cross Account Activity asset_type: AWS Account kill_chain_phases: diff --git a/detections/experimental/cloud/aws_detect_role_creation.yml b/detections/experimental/cloud/aws_detect_role_creation.yml index faa58d712b..437712762e 100644 --- a/detections/experimental/cloud/aws_detect_role_creation.yml +++ b/detections/experimental/cloud/aws_detect_role_creation.yml @@ -18,7 +18,7 @@ search: '`aws_cloudwatchlogs_eks` event_name=CreateRole action=created userIdent requestParameters.description responseElements.role.arn responseElements.role.createDate | `aws_detect_role_creation_filter`' tags: - analytics_story: + analytic_story: - AWS Cross Account Activity asset_type: AWS Account kill_chain_phases: diff --git a/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml b/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml index ff2c6c1461..ba946d2904 100644 --- a/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml +++ b/detections/experimental/cloud/aws_detect_sts_assume_role_abuse.yml @@ -16,7 +16,7 @@ search: '`cloudtrail` user_type=AssumedRole userIdentity.sessionContext.sessionI requestParameters.roleName responseElements.role.roleName responseElements.role.createDate | `aws_detect_sts_assume_role_abuse_filter`' tags: - analytics_story: + analytic_story: - AWS Cross Account Activity asset_type: AWS Account kill_chain_phases: diff --git a/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml b/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml index 0bcfd840ab..83f097a0a7 100644 --- a/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml +++ b/detections/experimental/cloud/aws_detect_sts_get_session_token_abuse.yml @@ -16,7 +16,7 @@ search: '`aws_cloudwatchlogs_eks` ASIA userIdentity.type=IAMUser| spath eventNa | search eventName=GetSessionToken | table sourceIPAddress eventTime userIdentity.arn userName userAgent user_type status region | `aws_detect_sts_get_session_token_abuse_filter`' tags: - analytics_story: + analytic_story: - AWS Cross Account Activity asset_type: AWS Account kill_chain_phases: diff --git a/detections/experimental/cloud/gcp_detect_accounts_with_high_risk_roles_by_project.yml b/detections/experimental/cloud/gcp_detect_accounts_with_high_risk_roles_by_project.yml index c898c77276..080e4b245f 100644 --- a/detections/experimental/cloud/gcp_detect_accounts_with_high_risk_roles_by_project.yml +++ b/detections/experimental/cloud/gcp_detect_accounts_with_high_risk_roles_by_project.yml @@ -22,7 +22,7 @@ search: '`google_gcp_pubsub_message` data.protoPayload.request.policy.bindings{} data.protoPayload.authorizationInfo{}.resource data.protoPayload.response.bindings{}.role data.protoPayload.response.bindings{}.members{} | `gcp_detect_accounts_with_high_risk_roles_by_project_filter`' tags: - analytics_story: + analytic_story: - GCP Cross Account Activity asset_type: GCP Account kill_chain_phases: diff --git a/detections/experimental/cloud/gcp_detect_gcploit_framework.yml b/detections/experimental/cloud/gcp_detect_gcploit_framework.yml index 342615feaa..f2665721ee 100644 --- a/detections/experimental/cloud/gcp_detect_gcploit_framework.yml +++ b/detections/experimental/cloud/gcp_detect_gcploit_framework.yml @@ -18,7 +18,7 @@ search: '`google_gcp_pubsub_message` data.protoPayload.request.function.timeout= data.protoPayload.authorizationInfo{}.permission data.protoPayload.request.location http_user_agent | `gcp_detect_gcploit_framework_filter`' tags: - analytics_story: + analytic_story: - GCP Cross Account Activity asset_type: GCP Account kill_chain_phases: diff --git a/detections/experimental/cloud/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/detections/experimental/cloud/gcp_detect_high_risk_permissions_by_resource_and_account.yml index 6f177179e9..d7a9364554 100644 --- a/detections/experimental/cloud/gcp_detect_high_risk_permissions_by_resource_and_account.yml +++ b/detections/experimental/cloud/gcp_detect_high_risk_permissions_by_resource_and_account.yml @@ -21,7 +21,7 @@ search: '`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.permi data.protoPayload.response.bindings{}.members{} data.resource.labels.project_id | `gcp_detect_high_risk_permissions_by_resource_and_account_filter`' tags: - analytics_story: + analytic_story: - GCP Cross Account Activity asset_type: GCP Account kill_chain_phases: diff --git a/detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml b/detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml index 67985d4e8a..1a48acc7e6 100644 --- a/detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml +++ b/detections/experimental/cloud/gcp_detect_oauth_token_abuse.yml @@ -17,7 +17,7 @@ search: '`google_gcp_pubsub_message` type.googleapis.com/google.cloud.audit.Audi |table protoPayload.@type protoPayload.status.details{}.@type protoPayload.status.details{}.violations{}.callerIp protoPayload.status.details{}.violations{}.type protoPayload.status.message | `gcp_detect_oauth_token_abuse_filter`' tags: - analytics_story: + analytic_story: - GCP Cross Account Activity asset_type: GCP Account kill_chain_phases: diff --git a/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml b/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml index bc7d1ee8c1..37adf4603b 100644 --- a/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml +++ b/detections/experimental/cloud/gcp_kubernetes_cluster_pod_scan_detection.yml @@ -13,7 +13,7 @@ search: '`google_gcp_pubsub_message` category=kube-audit |spath input=properties |search responseStatus.code=401 |table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod | `gcp_kubernetes_cluster_pod_scan_detection_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Scanning Activity asset_type: GCP Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/gcp_kubernetes_cluster_scan_detection.yml b/detections/experimental/cloud/gcp_kubernetes_cluster_scan_detection.yml index d2938ce1b1..413ed7e756 100644 --- a/detections/experimental/cloud/gcp_kubernetes_cluster_scan_detection.yml +++ b/detections/experimental/cloud/gcp_kubernetes_cluster_scan_detection.yml @@ -21,7 +21,7 @@ search: '`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerIp! as cluster_name| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `gcp_kubernetes_cluster_scan_detection_filter` ' tags: - analytics_story: + analytic_story: - Kubernetes Scanning Activity asset_type: GCP Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/detections/experimental/cloud/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml index 185f825d4a..fe3ecb853f 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml @@ -13,7 +13,7 @@ search: '`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts objectRe | table sourceIPs{} user.username userAgent verb annotations.authorization.k8s.io/decision | top sourceIPs{} user.username verb annotations.authorization.k8s.io/decision |`kubernetes_aws_detect_most_active_service_accounts_by_pod_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: AWS EKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_aws_detect_rbac_authorizations_by_account.yml b/detections/experimental/cloud/kubernetes_aws_detect_rbac_authorizations_by_account.yml index 42377b661f..7fff11e98d 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_rbac_authorizations_by_account.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_rbac_authorizations_by_account.yml @@ -15,7 +15,7 @@ search: '`aws_cloudwatchlogs_eks` annotations.authorization.k8s.io/reason=* | ta count by user.username annotations.authorization.k8s.io/reason | rare user.username annotations.authorization.k8s.io/reason |`kubernetes_aws_detect_rbac_authorization_by_account_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: AWS EKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_aws_detect_sensitive_object_access.yml b/detections/experimental/cloud/kubernetes_aws_detect_sensitive_object_access.yml index 80b1f6531e..38f6cd9fa3 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_sensitive_object_access.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_sensitive_object_access.yml @@ -14,7 +14,7 @@ search: '`aws_cloudwatchlogs_eks` objectRef.resource=secrets OR configmaps sourc objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason |dedup user.username user.groups{} |`aws_eks_kubernetes_cluster_sensitive_object_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: AWS EKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_aws_detect_sensitive_role_access.yml b/detections/experimental/cloud/kubernetes_aws_detect_sensitive_role_access.yml index c509d656e9..684a590f64 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_sensitive_role_access.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_sensitive_role_access.yml @@ -14,7 +14,7 @@ search: '`aws_cloudwatchlogs_eks` objectRef.resource=clusterroles OR clusterrole objectRef.namespace requestURI annotations.authorization.k8s.io/reason | dedup user.username user.groups{} |`kubernetes_aws_detect_sensitive_role_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: AWS EKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/detections/experimental/cloud/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml index 2bff8058f2..adb5dcef59 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml @@ -15,7 +15,7 @@ search: '`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts responseS = Failure | table sourceIPs{} user.username userAgent verb responseStatus.status requestURI | `kubernetes_aws_detect_service_accounts_forbidden_failure_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: AWS EKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml b/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml index 328d91f879..3b914725ce 100644 --- a/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml +++ b/detections/experimental/cloud/kubernetes_aws_detect_suspicious_kubectl_calls.yml @@ -14,7 +14,7 @@ search: '`aws_cloudwatchlogs_eks` userAgent=kubectl* sourceIPs{}!=127.0.0.1 sour src_user=system:anonymous | table src_ip src_user verb userAgent requestURI | stats count by src_ip src_user verb userAgent requestURI |`kubernetes_aws_detect_suspicious_kubectl_calls_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: AWS EKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml b/detections/experimental/cloud/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml index 53e190a670..604bd4ef4c 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml @@ -15,7 +15,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | s properties.pod objectRef.namespace | top sourceIPs{} user.username verb responseStatus.status properties.pod objectRef.namespace |`kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: Azure AKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_azure_detect_rbac_authorization_by_account.yml b/detections/experimental/cloud/kubernetes_azure_detect_rbac_authorization_by_account.yml index 6541322b48..411af9ca96 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_rbac_authorization_by_account.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_rbac_authorization_by_account.yml @@ -15,7 +15,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | s annotations.authorization.k8s.io/reason |stats count by user.username annotations.authorization.k8s.io/reason | rare user.username annotations.authorization.k8s.io/reason |`kubernetes_azure_detect_rbac_authorization_by_account_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: Azure AKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_azure_detect_sensitive_object_access.yml b/detections/experimental/cloud/kubernetes_azure_detect_sensitive_object_access.yml index ca217389bc..f7b65c99b8 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_sensitive_object_access.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_sensitive_object_access.yml @@ -14,7 +14,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log| se user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason |dedup user.username user.groups{} |`kubernetes_azure_detect_sensitive_object_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: Azure AKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_azure_detect_sensitive_role_access.yml b/detections/experimental/cloud/kubernetes_azure_detect_sensitive_role_access.yml index 5d409fa81f..e317f69ed8 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_sensitive_role_access.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_sensitive_role_access.yml @@ -14,7 +14,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log| se user.groups{} objectRef.namespace requestURI annotations.authorization.k8s.io/reason | dedup user.username user.groups{} |`kubernetes_azure_detect_sensitive_role_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: Azure AKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/detections/experimental/cloud/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml index 9c02063a2a..bb7bc925d7 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml @@ -14,7 +14,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | s user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace |`kubernetes_azure_detect_service_accounts_forbidden_failure_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: Azure AKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/detections/experimental/cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml index c314dfc0f5..a2f2545c43 100644 --- a/detections/experimental/cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml +++ b/detections/experimental/cloud/kubernetes_azure_detect_suspicious_kubectl_calls.yml @@ -17,7 +17,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | s rare sourceIPs{} verb userAgent user.groups{} objectRef.resource objectRef.namespace requestURI |`kubernetes_azure_detect_suspicious_kubectl_calls_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: Azure AKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_azure_pod_scan_fingerprint.yml b/detections/experimental/cloud/kubernetes_azure_pod_scan_fingerprint.yml index 10a15822bb..7c1bfa2c24 100644 --- a/detections/experimental/cloud/kubernetes_azure_pod_scan_fingerprint.yml +++ b/detections/experimental/cloud/kubernetes_azure_pod_scan_fingerprint.yml @@ -14,7 +14,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | s responseStatus.code=401 | table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod |`kubernetes_azure_pod_scan_fingerprint_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Scanning Activity asset_type: Azure AKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_azure_scan_fingerprint.yml b/detections/experimental/cloud/kubernetes_azure_scan_fingerprint.yml index 6b94cf8a0e..2ba0d56c96 100644 --- a/detections/experimental/cloud/kubernetes_azure_scan_fingerprint.yml +++ b/detections/experimental/cloud/kubernetes_azure_scan_fingerprint.yml @@ -14,7 +14,7 @@ search: '`kubernetes_azure` category=kube-audit | spath input=properties.log | s responseStatus.code=401 | table sourceIPs{} userAgent verb requestURI responseStatus.reason |`kubernetes_azure_scan_fingerprint_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Scanning Activity asset_type: Azure AKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_RBAC_authorizations_by_account.yml b/detections/experimental/cloud/kubernetes_gcp_detect_RBAC_authorizations_by_account.yml index cfae68d390..81c324f49b 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_RBAC_authorizations_by_account.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_RBAC_authorizations_by_account.yml @@ -15,7 +15,7 @@ search: '`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=Clu data.labels.authorization.k8s.io/reason | rare src_user data.labels.authorization.k8s.io/reason |`kubernetes_gcp_detect_rbac_authorizations_by_account_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: GCP GKE Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/detections/experimental/cloud/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml index cc4c387988..817d6f791f 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml @@ -15,7 +15,7 @@ search: '`google_gcp_pubsub_message` data.protoPayload.request.spec.group{}=sys | top src_ip src_user http_user_agent data.labels.authorization.k8s.io/decision data.protoPayload.response.spec.resourceAttributes.resource |`kubernetes_gcp_detect_most_active_service_accounts_by_pod_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: GCP GKE Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_object_access.yml b/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_object_access.yml index 28886209e1..30b5635af1 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_object_access.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_object_access.yml @@ -15,7 +15,7 @@ search: '`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.resou | dedup data.protoPayload.requestMetadata.callerIp src_user data.resource.labels.cluster_name |`kubernetes_gcp_detect_sensitive_object_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: GCP GKE Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_role_access.yml b/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_role_access.yml index 1a498bd5bd..e5847fab8d 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_role_access.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_sensitive_role_access.yml @@ -15,7 +15,7 @@ search: '`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=Clu src_user http_user_agent data.labels.authorization.k8s.io/decision data.labels.authorization.k8s.io/reason | dedup src_ip src_user |`kubernetes_gcp_detect_sensitive_role_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Role Activity asset_type: GCP GKE EKS Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/detections/experimental/cloud/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml index 0881af5018..1c3d612ab8 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml @@ -17,7 +17,7 @@ search: '`google_gcp_pubsub_message` system:serviceaccounts data.protoPayload.re data.protoPayload.response.status.reason data.labels.authorization.k8s.io/decision | dedup src_ip src_user | `kubernetes_gcp_detect_service_accounts_forbidden_failure_access_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: GCP GKE Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/detections/experimental/cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml index 88e1c2c1d5..f9518a66af 100644 --- a/detections/experimental/cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml +++ b/detections/experimental/cloud/kubernetes_gcp_detect_suspicious_kubectl_calls.yml @@ -16,7 +16,7 @@ search: '`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerSup data.protoPayload.authorizationInfo{}.granted object_path |dedup src_ip src_user |`kubernetes_gcp_detect_suspicious_kubectl_calls_filter`' tags: - analytics_story: + analytic_story: - Kubernetes Sensitive Object Access Activity asset_type: GCP GKE Kubernetes cluster kill_chain_phases: diff --git a/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml b/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml index fac60dc1f3..a6386f3c07 100644 --- a/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml +++ b/detections/experimental/endpoint/child_processes_of_spoolsv_exe.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count values(Processes.proces Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `child_processes_of_spoolsv_exe_filter` ' tags: - analytics_story: + analytic_story: - Windows Privilege Escalation asset_type: Endpoint cis20: diff --git a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml index e8289afe14..d80b2412bb 100644 --- a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml +++ b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156.yml @@ -12,7 +12,7 @@ references: - https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit search: '`linux_hosts` | search "sudoedit -s \\" | `detect_baron_samedit_cve_2021_3156_filter`' tags: - analytics_story: + analytic_story: - Baron Samedit CVE-2021-3156 asset_type: Endpoint cis20: diff --git a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml index f169d084b0..21b13143a0 100644 --- a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml +++ b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml @@ -15,7 +15,7 @@ references: search: '`linux_hosts` | search sudoedit segfault | stats count min(_time) as firstTime max(_time) as lastTime by host | search count > 5 | `detect_baron_samedit_cve_2021_3156_segfault_filter`' tags: - analytics_story: + analytic_story: - Baron Samedit CVE-2021-3156 asset_type: Endpoint cis20: diff --git a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml index 8e87b4bbb9..8f1b6b2728 100644 --- a/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml +++ b/detections/experimental/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml @@ -12,7 +12,7 @@ references: - https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit search: '`osquery_process` | search "columns.cmdline"="sudoedit -s \\*" | `detect_baron_samedit_cve_2021_3156_via_osquery_filter`' tags: - analytics_story: + analytic_story: - Baron Samedit CVE-2021-3156 asset_type: Endpoint cis20: diff --git a/detections/experimental/endpoint/detect_oulook_exe_writing_a__zip_file.yml b/detections/experimental/endpoint/detect_oulook_exe_writing_a__zip_file.yml index eaa0deb7e3..f14dedc7cf 100644 --- a/detections/experimental/endpoint/detect_oulook_exe_writing_a__zip_file.yml +++ b/detections/experimental/endpoint/detect_oulook_exe_writing_a__zip_file.yml @@ -27,7 +27,7 @@ search: '| tstats `security_content_summariesonly` min(_time) as firstTime max( outlook_id process_name parent_process_name file_name file_path | where file_name != "" | `detect_oulook_exe_writing_a__zip_file_filter` ' tags: - analytics_story: + analytic_story: - Phishing Payloads asset_type: Endpoint cis20: diff --git a/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml b/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml index f476e6aaf0..a7152d772f 100644 --- a/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml +++ b/detections/experimental/endpoint/detection_of_tools_built_by_nirsoft.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) values(Proce Processes.user | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `detection_of_tools_built_by_nirsoft_filter`' tags: - analytics_story: + analytic_story: - 'Emotet Malware DHS Report TA18-201A ' asset_type: Endpoint cis20: diff --git a/detections/experimental/endpoint/first_time_seen_running_windows_service.yml b/detections/experimental/endpoint/first_time_seen_running_windows_service.yml index 191aeff369..973138e485 100644 --- a/detections/experimental/endpoint/first_time_seen_running_windows_service.yml +++ b/detections/experimental/endpoint/first_time_seen_running_windows_service.yml @@ -22,7 +22,7 @@ search: '`wineventlog_system` EventCode=7036 | rex field=Message "The (? relative_time(now(), `previously_seen_windows_services_window`) | table _time dest service | `first_time_seen_running_windows_service_filter`' tags: - analytics_story: + analytic_story: - Windows Service Abuse - Orangeworm Attack Group - Sunburst Malware diff --git a/detections/experimental/endpoint/processes_tapping_keyboard_events.yml b/detections/experimental/endpoint/processes_tapping_keyboard_events.yml index 641864eb0e..f51b407e15 100644 --- a/detections/experimental/endpoint/processes_tapping_keyboard_events.yml +++ b/detections/experimental/endpoint/processes_tapping_keyboard_events.yml @@ -20,7 +20,7 @@ search: '| from datamodel Alerts.Alerts | search app=osquery:results name=pack_o | rename columns.cmdline as cmd, columns.name as process_name, columns.pid as process_id| dedup host,process_name | table host,process_name, cmd, process_id | `processes_tapping_keyboard_events_filter`' tags: - analytics_story: + analytic_story: - ColdRoot MacOS RAT asset_type: Endpoint cis20: diff --git a/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml b/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml index e0956c50ba..7a25bed265 100644 --- a/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml +++ b/detections/experimental/endpoint/remote_desktop_process_running_on_system.yml @@ -22,7 +22,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime Processes.process | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `drop_dm_object_name(Processes)` | `remote_desktop_process_running_on_system_filter` ' tags: - analytics_story: + analytic_story: - Hidden Cobra Malware - Lateral Movement asset_type: Endpoint diff --git a/detections/experimental/endpoint/spike_in_file_writes.yml b/detections/experimental/endpoint/spike_in_file_writes.yml index 272b9dcc3a..b1479661ed 100644 --- a/detections/experimental/endpoint/spike_in_file_writes.yml +++ b/detections/experimental/endpoint/spike_in_file_writes.yml @@ -21,7 +21,7 @@ search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint count, null))) as stdev by "dest" | eval upperBound=(avg+stdev*4), isOutlier=if((count > upperBound) AND num_data_samples >=20, 1, 0) | search isOutlier=1 | `spike_in_file_writes_filter` ' tags: - analytics_story: + analytic_story: - SamSam Ransomware - Ryuk Ransomware - Ransomware diff --git a/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml b/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml index ebecad16b1..14fe6bf28a 100644 --- a/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml +++ b/detections/experimental/endpoint/sunburst_correlation_dll_and_network_event.yml @@ -19,7 +19,7 @@ search: '(`sysmon` EventCode=7 ImageLoaded=*SolarWinds.Orion.Core.BusinessLayer. host as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `sunburst_correlation_dll_and_network_event_filter` ' tags: - analytics_story: + analytic_story: - Sunburst Malware asset_type: Windows cis20: diff --git a/detections/experimental/endpoint/wmi_permanent_event_subscription.yml b/detections/experimental/endpoint/wmi_permanent_event_subscription.yml index 9ce48984c9..c5067ccb86 100644 --- a/detections/experimental/endpoint/wmi_permanent_event_subscription.yml +++ b/detections/experimental/endpoint/wmi_permanent_event_subscription.yml @@ -15,7 +15,7 @@ search: '`wmi` EventCode=5861 Binding | rex field=Message "Consumer =\s+(?50 | `excessive_dns_failures_filter`' tags: - analytics_story: + analytic_story: - Suspicious DNS Traffic - Command and Control asset_type: Endpoint diff --git a/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml b/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml index 02a46ddc8a..d1c101507d 100644 --- a/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml +++ b/detections/experimental/network/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml @@ -31,7 +31,7 @@ search: '| tstats `security_content_summariesonly` sum(All_Traffic.bytes_in) as | table src_ip, _time, bytes_in, avg_bytes_in, per_source_avg_bytes_in, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average | `hosts_receiving_high_volume_of_network_traffic_from_email_server_filter`' tags: - analytics_story: + analytic_story: - Collection and Staging asset_type: Endpoint cis20: diff --git a/detections/experimental/network/large_volume_of_dns_any_queries.yml b/detections/experimental/network/large_volume_of_dns_any_queries.yml index da2a6ac060..ed30b4882e 100644 --- a/detections/experimental/network/large_volume_of_dns_any_queries.yml +++ b/detections/experimental/network/large_volume_of_dns_any_queries.yml @@ -14,7 +14,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Network_ where nodename=DNS "DNS.message_type"="QUERY" "DNS.record_type"="ANY" by "DNS.dest" | `drop_dm_object_name("DNS")` | where count>200 | `large_volume_of_dns_any_queries_filter`' tags: - analytics_story: + analytic_story: - DNS Amplification Attacks asset_type: DNS Servers cis20: diff --git a/detections/experimental/network/prohibited_network_traffic_allowed.yml b/detections/experimental/network/prohibited_network_traffic_allowed.yml index d45f488cb3..8410fd7c14 100644 --- a/detections/experimental/network/prohibited_network_traffic_allowed.yml +++ b/detections/experimental/network/prohibited_network_traffic_allowed.yml @@ -20,7 +20,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime OUTPUT app is_prohibited note transport | search is_prohibited=true | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name("All_Traffic")` | `prohibited_network_traffic_allowed_filter`' tags: - analytics_story: + analytic_story: - Prohibited Traffic Allowed or Protocol Mismatch - Ransomware - Command and Control diff --git a/detections/experimental/network/protocol_or_port_mismatch.yml b/detections/experimental/network/protocol_or_port_mismatch.yml index a464c99729..9025411078 100644 --- a/detections/experimental/network/protocol_or_port_mismatch.yml +++ b/detections/experimental/network/protocol_or_port_mismatch.yml @@ -23,7 +23,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime All_Traffic.dest_port |`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name("All_Traffic")` | `protocol_or_port_mismatch_filter`' tags: - analytics_story: + analytic_story: - Prohibited Traffic Allowed or Protocol Mismatch - Command and Control asset_type: Endpoint diff --git a/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml b/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml index a6c304658f..f86378c8e7 100644 --- a/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml +++ b/detections/experimental/network/protocols_passing_authentication_in_cleartext.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime All_Traffic.src All_Traffic.dest All_Traffic.dest_port | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name("All_Traffic")` | `protocols_passing_authentication_in_cleartext_filter`' tags: - analytics_story: + analytic_story: - Use of Cleartext Protocols asset_type: Endpoint cis20: diff --git a/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml b/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml index 20679c8362..2dfc224b23 100644 --- a/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml +++ b/detections/experimental/web/detect_attackers_scanning_for_vulnerable_jboss_servers.yml @@ -16,7 +16,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime OR Web.url = "*invoker*") by Web.http_method, Web.url, Web.src, Web.dest | `drop_dm_object_name("Web")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_attackers_scanning_for_vulnerable_jboss_servers_filter`' tags: - analytics_story: + analytic_story: - JBoss Vulnerability - SamSam Ransomware asset_type: Web Server diff --git a/detections/experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml b/detections/experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml index 376f240dd2..4b7e72d52e 100644 --- a/detections/experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml +++ b/detections/experimental/web/detect_f5_tmui_rct_cve_2020_5902.yml @@ -18,7 +18,7 @@ references: - https://blog.cloudflare.com/cve-2020-5902-helping-to-protect-against-the-f5-tmui-rce-vulnerability/ search: '`f5_bigip_rogue` | regex _raw="(hsqldb;|.*\\.\\.;.*)" | search `detect_f5_tmui_rce_cve_2020_5902_filter`' tags: - analytics_story: + analytic_story: - F5 TMUI RCE CVE-2020-5902 asset_type: Network cis20: diff --git a/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml b/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml index 7e3b5f3620..ae202aff6e 100644 --- a/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml +++ b/detections/experimental/web/detect_malicious_requests_to_exploit_jboss_servers.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `security_content_ctime(lastTime)` | table src, dest_ip, http_method, url, firstTime, lastTime | `detect_malicious_requests_to_exploit_jboss_servers_filter`' tags: - analytics_story: + analytic_story: - JBoss Vulnerability - SamSam Ransomware asset_type: Web Server diff --git a/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml b/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml index d0a0782bee..ba509e06ce 100644 --- a/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml +++ b/detections/experimental/web/monitor_web_traffic_for_brand_abuse.yml @@ -14,7 +14,7 @@ search: '| tstats `security_content_summariesonly` values(Web.url) as urls min(_ as firstTime from datamodel=Web by Web.src | `drop_dm_object_name("Web")` | `security_content_ctime(firstTime)` | `brand_abuse_web` | `monitor_web_traffic_for_brand_abuse_filter`' tags: - analytics_story: + analytic_story: - Brand Monitoring asset_type: Endpoint cis20: diff --git a/detections/experimental/web/sql_injection_with_long_urls.yml b/detections/experimental/web/sql_injection_with_long_urls.yml index 6eaab1f346..640fd10dd8 100644 --- a/detections/experimental/web/sql_injection_with_long_urls.yml +++ b/detections/experimental/web/sql_injection_with_long_urls.yml @@ -27,7 +27,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Web wher + mvcount(split(url, "select%20top")) + mvcount(split(url, "union")) + mvcount(split(url, "xp_cmdshell")) - 24 | where num_sql_cmds > 3 | `sql_injection_with_long_urls_filter`' tags: - analytics_story: + analytic_story: - SQL Injection asset_type: Database Server cis20: diff --git a/detections/experimental/web/supernova_webshell.yml b/detections/experimental/web/supernova_webshell.yml index 3614d87ea3..8b17175e8a 100644 --- a/detections/experimental/web/supernova_webshell.yml +++ b/detections/experimental/web/supernova_webshell.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Web.Web Web.src Web.dest Web.url Web.vendor_product Web.user Web.http_user_agent _time span=1s | `supernova_webshell_filter`' tags: - analytics_story: + analytic_story: - Sunburst Malware cis20: - CIS 4 diff --git a/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml b/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml index 2d7002fbbc..fcddb27b2d 100644 --- a/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml +++ b/detections/network/detect_hosts_connecting_to_dynamic_domain_providers.yml @@ -40,7 +40,7 @@ search: '| tstats `security_content_summariesonly` count values(DNS.answer) as a min(_time) as firstTime from datamodel=Network_Resolution by DNS.query host | `drop_dm_object_name("DNS")` | `security_content_ctime(firstTime)` | `dynamic_dns_providers` | `detect_hosts_connecting_to_dynamic_domain_providers_filter`' tags: - analytics_story: + analytic_story: - Data Protection - Prohibited Traffic Allowed or Protocol Mismatch - DNS Hijacking diff --git a/detections/network/detect_ipv6_network_infrastructure_threats.yml b/detections/network/detect_ipv6_network_infrastructure_threats.yml index afd2cff2bf..7b95a6aafd 100644 --- a/detections/network/detect_ipv6_network_infrastructure_threats.yml +++ b/detections/network/detect_ipv6_network_infrastructure_threats.yml @@ -31,7 +31,7 @@ search: '`cisco_networks` facility="SISF" mnemonic IN ("IP_THEFT","MAC_THEFT","M action count | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `detect_ipv6_network_infrastructure_threats_filter`' tags: - analytics_story: + analytic_story: - Router and Infrastructure Security asset_type: Infrastructure cis20: diff --git a/detections/network/detect_large_outbound_icmp_packets.yml b/detections/network/detect_large_outbound_icmp_packets.yml index a2975c2f3e..aa6664c5f7 100644 --- a/detections/network/detect_large_outbound_icmp_packets.yml +++ b/detections/network/detect_large_outbound_icmp_packets.yml @@ -31,7 +31,7 @@ search: '| tstats `security_content_summariesonly` count earliest(_time) as firs | search ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | `detect_large_outbound_icmp_packets_filter`' tags: - analytics_story: + analytic_story: - Command and Control asset_type: Endpoint cis20: diff --git a/detections/network/detect_outbound_smb_traffic.yml b/detections/network/detect_outbound_smb_traffic.yml index d566276dfc..d4e624dfcf 100644 --- a/detections/network/detect_outbound_smb_traffic.yml +++ b/detections/network/detect_outbound_smb_traffic.yml @@ -34,7 +34,7 @@ search: '| tstats `security_content_summariesonly` earliest(_time) as start_time All_Traffic.src_ip | `drop_dm_object_name("All_Traffic")` | `security_content_ctime(start_time)` | `security_content_ctime(end_time)` | `detect_outbound_smb_traffic_filter`' tags: - analytics_story: + analytic_story: - Hidden Cobra Malware - DHS Report TA18-074A - Sunburst Malware diff --git a/detections/network/detect_port_security_violation.yml b/detections/network/detect_port_security_violation.yml index 148a3a62ed..81a1babeeb 100644 --- a/detections/network/detect_port_security_violation.yml +++ b/detections/network/detect_port_security_violation.yml @@ -29,7 +29,7 @@ search: '`cisco_networks` (facility="PM" mnemonic="ERR_DISABLE" disable_cause="p src_mac values(src_vlan) AS src_vlan values(action) AS action count by host src_interface | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_port_security_violation_filter`' tags: - analytics_story: + analytic_story: - Router and Infrastructure Security asset_type: Infrastructure cis20: diff --git a/detections/network/detect_rogue_dhcp_server.yml b/detections/network/detect_rogue_dhcp_server.yml index 071793c609..a000876cb0 100644 --- a/detections/network/detect_rogue_dhcp_server.yml +++ b/detections/network/detect_rogue_dhcp_server.yml @@ -20,7 +20,7 @@ search: '`cisco_networks` facility="DHCP_SNOOPING" mnemonic="DHCP_SNOOPING_UNTRU AS message_type values(src_mac) AS src_mac BY host | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| `detect_rogue_dhcp_server_filter`' tags: - analytics_story: + analytic_story: - Router and Infrastructure Security asset_type: Infrastructure cis20: diff --git a/detections/network/detect_snicat_sni_exfiltration.yml b/detections/network/detect_snicat_sni_exfiltration.yml index 75fe591e81..32a6c39b62 100644 --- a/detections/network/detect_snicat_sni_exfiltration.yml +++ b/detections/network/detect_snicat_sni_exfiltration.yml @@ -19,7 +19,7 @@ search: '`zeek_ssl` | rex field=server_name "(?(LIST|LS|SIZE|LD|CB|CD|EX | stats count by src_ip dest_ip server_name snicat | where count>0 | table src_ip dest_ip server_name snicat | `detect_snicat_sni_exfiltration_filter`' tags: - analytics_story: + analytic_story: - Data Exfiltration asset_type: Network cis20: diff --git a/detections/network/detect_software_download_to_network_device.yml b/detections/network/detect_software_download_to_network_device.yml index 31bebc0731..b95a5e8c22 100644 --- a/detections/network/detect_software_download_to_network_device.yml +++ b/detections/network/detect_software_download_to_network_device.yml @@ -25,7 +25,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by All_Traffic.src All_Traffic.dest All_Traffic.dest_port | `drop_dm_object_name("All_Traffic")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `detect_software_download_to_network_device_filter`' tags: - analytics_story: + analytic_story: - Router and Infrastructure Security asset_type: Infrastructure cis20: diff --git a/detections/network/detect_traffic_mirroring.yml b/detections/network/detect_traffic_mirroring.yml index 8fcbc0d809..019767c04a 100644 --- a/detections/network/detect_traffic_mirroring.yml +++ b/detections/network/detect_traffic_mirroring.yml @@ -23,7 +23,7 @@ search: '`cisco_networks` (facility="MIRROR" mnemonic="ETH_SPAN_SESSION_UP") OR count BY host facility mnemonic | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | `detect_traffic_mirroring_filter`' tags: - analytics_story: + analytic_story: - Router and Infrastructure Security asset_type: Infrastructure cis20: diff --git a/detections/network/detect_unauthorized_assets_by_mac_address.yml b/detections/network/detect_unauthorized_assets_by_mac_address.yml index 759565ea52..4864991118 100644 --- a/detections/network/detect_unauthorized_assets_by_mac_address.yml +++ b/detections/network/detect_unauthorized_assets_by_mac_address.yml @@ -25,7 +25,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Network_ | search NOT [| inputlookup asset_lookup_by_str |rename mac as dest_mac | fields + dest_mac] | `detect_unauthorized_assets_by_mac_address_filter`' tags: - analytics_story: + analytic_story: - Asset Tracking asset_type: Infrastructure cis20: diff --git a/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml b/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml index 878a7546ee..1503f7d206 100644 --- a/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml +++ b/detections/network/detect_windows_dns_sigred_via_splunk_stream.yml @@ -15,7 +15,7 @@ search: '`stream_dns` | spath "query_type{}" | search "query_type{}" IN (SIG,KEY bytes_out>65000] | `detect_windows_dns_sigred_via_splunk_stream_filter` | stats count by flow_id | where count>1 | fields - count' tags: - analytics_story: + analytic_story: - Windows DNS SIGRed CVE-2020-1350 asset_type: Endpoint cis20: diff --git a/detections/network/detect_windows_dns_sigred_via_zeek.yml b/detections/network/detect_windows_dns_sigred_via_zeek.yml index 6d61903c98..742026113d 100644 --- a/detections/network/detect_windows_dns_sigred_via_zeek.yml +++ b/detections/network/detect_windows_dns_sigred_via_zeek.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Network_ as flow_id] | `detect_windows_dns_sigred_via_zeek_filter` | stats count by flow_id | where count>1 | fields - count ' tags: - analytics_story: + analytic_story: - Windows DNS SIGRed CVE-2020-1350 asset_type: Endpoint cis20: diff --git a/detections/network/detect_zerologon_via_zeek.yml b/detections/network/detect_zerologon_via_zeek.yml index e45df9cfa5..dc4e3b6fdd 100644 --- a/detections/network/detect_zerologon_via_zeek.yml +++ b/detections/network/detect_zerologon_via_zeek.yml @@ -19,7 +19,7 @@ search: '`zeek_rpc` operation IN (NetrServerPasswordSet2,NetrServerReqChallenge, as passcount count as totalcount by _time,src_ip,dest_ip | search opscount=3 authcount>4 passcount>0 | search `detect_zerologon_via_zeek_filter`' tags: - analytics_story: + analytic_story: - Detect Zerologon Attack asset_type: Network cis20: diff --git a/detections/network/dns_query_length_outliers___mltk.yml b/detections/network/dns_query_length_outliers___mltk.yml index 26f9aedd28..68c7227903 100644 --- a/detections/network/dns_query_length_outliers___mltk.yml +++ b/detections/network/dns_query_length_outliers___mltk.yml @@ -44,7 +44,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as start_tim as isOutlier | search isOutlier > 0 | sort -query_length | table start_time end_time query record_type count src dest query_length | `dns_query_length_outliers___mltk_filter` ' tags: - analytics_story: + analytic_story: - Hidden Cobra Malware - Suspicious DNS Traffic - Command and Control diff --git a/detections/network/dns_query_length_with_high_standard_deviation.yml b/detections/network/dns_query_length_with_high_standard_deviation.yml index b9c8be8c1f..2a1be60dd7 100644 --- a/detections/network/dns_query_length_with_high_standard_deviation.yml +++ b/detections/network/dns_query_length_with_high_standard_deviation.yml @@ -15,7 +15,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Network_ avg(query_length) AS avg p50(query_length) AS p50| where query_length>(avg+stdev*2) | eval z_score=(query_length-avg)/stdev | `dns_query_length_with_high_standard_deviation_filter` ' tags: - analytics_story: + analytic_story: - Hidden Cobra Malware - Suspicious DNS Traffic - Command and Control diff --git a/detections/network/remote_desktop_network_bruteforce.yml b/detections/network/remote_desktop_network_bruteforce.yml index b0335dca10..93bd893b49 100644 --- a/detections/network/remote_desktop_network_bruteforce.yml +++ b/detections/network/remote_desktop_network_bruteforce.yml @@ -17,7 +17,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime AS src All_Traffic.dest AS dest | table firstTime lastTime src dest count avg p50 stdev | `remote_desktop_network_bruteforce_filter`' tags: - analytics_story: + analytic_story: - SamSam Ransomware - Ryuk Ransomware asset_type: Endpoint diff --git a/detections/network/remote_desktop_network_traffic.yml b/detections/network/remote_desktop_network_traffic.yml index 8089eaa93f..117724ee23 100644 --- a/detections/network/remote_desktop_network_traffic.yml +++ b/detections/network/remote_desktop_network_traffic.yml @@ -24,7 +24,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime by All_Traffic.src All_Traffic.dest All_Traffic.dest_port | `drop_dm_object_name("All_Traffic")` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `remote_desktop_network_traffic_filter` ' tags: - analytics_story: + analytic_story: - SamSam Ransomware - Ryuk Ransomware - Hidden Cobra Malware diff --git a/detections/network/smb_traffic_spike.yml b/detections/network/smb_traffic_spike.yml index 982c7065e6..797fb5b144 100644 --- a/detections/network/smb_traffic_spike.yml +++ b/detections/network/smb_traffic_spike.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count from datamodel=Network_ null))) as stdev by src | eval upperBound=(avg+stdev*2), isOutlier=if(count > upperBound AND num_data_samples >=50, 1, 0) | where isOutlier=1 | table src count | `smb_traffic_spike_filter` ' tags: - analytics_story: + analytic_story: - 'Emotet Malware DHS Report TA18-201A ' - Hidden Cobra Malware - Ransomware diff --git a/detections/network/smb_traffic_spike___mltk.yml b/detections/network/smb_traffic_spike___mltk.yml index cd352d9610..cff80cd4fb 100644 --- a/detections/network/smb_traffic_spike___mltk.yml +++ b/detections/network/smb_traffic_spike___mltk.yml @@ -39,7 +39,7 @@ search: '| tstats `security_content_summariesonly` count values(All_Traffic.dest | rename "IsOutlier(count)" as isOutlier | search isOutlier > 0 | sort -count | table _time src dest port count | `smb_traffic_spike___mltk_filter` ' tags: - analytics_story: + analytic_story: - 'Emotet Malware DHS Report TA18-201A ' - Hidden Cobra Malware - Ransomware diff --git a/detections/network/tor_traffic.yml b/detections/network/tor_traffic.yml index c230afe231..bb5ff72383 100644 --- a/detections/network/tor_traffic.yml +++ b/detections/network/tor_traffic.yml @@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name("All_Traffic")` | `tor_traffic_filter`' tags: - analytics_story: + analytic_story: - Prohibited Traffic Allowed or Protocol Mismatch - Ransomware - Command and Control diff --git a/detections/network/unusually_long_content_type_length.yml b/detections/network/unusually_long_content_type_length.yml index 78c7882317..413c50b9d0 100644 --- a/detections/network/unusually_long_content_type_length.yml +++ b/detections/network/unusually_long_content_type_length.yml @@ -14,7 +14,7 @@ search: '`stream_http` | eval cs_content_type_length = len(cs_content_type) | wh cs_content_type_length > 100 | table endtime src_ip dest_ip cs_content_type_length cs_content_type url | `unusually_long_content_type_length_filter`' tags: - analytics_story: + analytic_story: - Apache Struts Vulnerability asset_type: Web Server cis20: diff --git a/detections/web/web_fraud___account_harvesting.yml b/detections/web/web_fraud___account_harvesting.yml index d667c4e10b..66fa083ecf 100644 --- a/detections/web/web_fraud___account_harvesting.yml +++ b/detections/web/web_fraud___account_harvesting.yml @@ -32,7 +32,7 @@ search: '`stream_http` http_content_type=text* uri="/magento2/customer/account/l as UniqueUsernames list(Username) as src_user by email_domain | where UniqueUsernames> 25 | `web_fraud___account_harvesting_filter`' tags: - analytics_story: + analytic_story: - Web Fraud Detection asset_type: Account cis20: diff --git a/detections/web/web_fraud___anomalous_user_clickspeed.yml b/detections/web/web_fraud___anomalous_user_clickspeed.yml index a031ddb7eb..ed33dd989b 100644 --- a/detections/web/web_fraud___anomalous_user_clickspeed.yml +++ b/detections/web/web_fraud___anomalous_user_clickspeed.yml @@ -28,7 +28,7 @@ search: '`stream_http` http_content_type=text* | rex field=cookie "form_key=(?5 AND (ClickSpeedStdDev<.5 OR ClickSpeedAvg<.5) | `web_fraud___anomalous_user_clickspeed_filter`' tags: - analytics_story: + analytic_story: - Web Fraud Detection asset_type: account cis20: diff --git a/detections/web/web_fraud___password_sharing_across_accounts.yml b/detections/web/web_fraud___password_sharing_across_accounts.yml index 3dfdfdd9c1..ddebd70164 100644 --- a/detections/web/web_fraud___password_sharing_across_accounts.yml +++ b/detections/web/web_fraud___password_sharing_across_accounts.yml @@ -23,7 +23,7 @@ search: '`stream_http` http_content_type=text* uri=/magento2/customer/account/lo values(Username) as user list(src_ip) as src_ip by Password|where UniqueUsernames>5 | `web_fraud___password_sharing_across_accounts_filter`' tags: - analytics_story: + analytic_story: - Web Fraud Detection asset_type: account cis20: