mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Add updated schemas, which has been updated as manual_review content was resolved
This commit is contained in:
@@ -133,7 +133,9 @@
|
||||
"Baseline Of Kubernetes Process Resource",
|
||||
"Baseline Of Kubernetes Process Resource Ratio",
|
||||
"Baseline Of Open S3 Bucket Decommissioning",
|
||||
"Baseline of Network ACL Activity by ARN",
|
||||
"Baseline of S3 Bucket deletion activity by ARN",
|
||||
"Baseline of Security Group Activity by ARN",
|
||||
"Baseline of blocked outbound traffic from AWS",
|
||||
"BishopFox Sliver Adversary Emulation Framework",
|
||||
"Black Basta Ransomware",
|
||||
@@ -216,6 +218,7 @@
|
||||
"ConnectWise ScreenConnect Vulnerabilities",
|
||||
"Count of Unique IPs Connecting to Ports",
|
||||
"Count of assets by category",
|
||||
"Create a list of approved AWS service accounts",
|
||||
"Credential Dumping",
|
||||
"Critical Alerts",
|
||||
"CrowdStrike Falcon Stream Alert",
|
||||
@@ -227,6 +230,7 @@
|
||||
"DHS Report TA18-074A",
|
||||
"DNS Amplification Attacks",
|
||||
"DNS Hijacking",
|
||||
"DNSTwist Domain Names",
|
||||
"DarkCrystal RAT",
|
||||
"DarkGate Malware",
|
||||
"DarkSide Ransomware",
|
||||
@@ -241,6 +245,7 @@
|
||||
"Detect Zerologon Attack",
|
||||
"Dev Sec Ops",
|
||||
"Disabling Security Tools",
|
||||
"Discover DNS records",
|
||||
"Disk Wiper",
|
||||
"Domain Trust Discovery",
|
||||
"Double Zero Destructor",
|
||||
@@ -439,6 +444,7 @@
|
||||
"Previously Seen Zoom Child Processes - Initial",
|
||||
"Previously Seen Zoom Child Processes - Update",
|
||||
"Previously seen S3 bucket access by remote IP",
|
||||
"Previously seen command line arguments",
|
||||
"PrintNightmare CVE-2021-34527",
|
||||
"Prohibited Traffic Allowed or Protocol Mismatch",
|
||||
"PromptFlux",
|
||||
@@ -2892,10 +2898,15 @@
|
||||
"Baseline Of Kubernetes Process Resource",
|
||||
"Baseline Of Kubernetes Process Resource Ratio",
|
||||
"Baseline Of Open S3 Bucket Decommissioning",
|
||||
"Baseline of Network ACL Activity by ARN",
|
||||
"Baseline of S3 Bucket deletion activity by ARN",
|
||||
"Baseline of Security Group Activity by ARN",
|
||||
"Baseline of blocked outbound traffic from AWS",
|
||||
"Count of Unique IPs Connecting to Ports",
|
||||
"Count of assets by category",
|
||||
"Create a list of approved AWS service accounts",
|
||||
"DNSTwist Domain Names",
|
||||
"Discover DNS records",
|
||||
"Identify Systems Creating Remote Desktop Traffic",
|
||||
"Identify Systems Receiving Remote Desktop Traffic",
|
||||
"Identify Systems Using Remote Desktop",
|
||||
@@ -2920,6 +2931,7 @@
|
||||
"Previously Seen Zoom Child Processes - Initial",
|
||||
"Previously Seen Zoom Child Processes - Update",
|
||||
"Previously seen S3 bucket access by remote IP",
|
||||
"Previously seen command line arguments",
|
||||
"Windows Updates Install Failures",
|
||||
"Windows Updates Install Successes"
|
||||
],
|
||||
|
||||
@@ -2361,7 +2361,8 @@
|
||||
"description": "PlayBook Type field.\n\nThis is intentionally different than the Type Enum\nabove due to legacy naming in the playbook files.",
|
||||
"enum": [
|
||||
"Automation",
|
||||
"Input"
|
||||
"Input",
|
||||
"Enterprise Security"
|
||||
],
|
||||
"title": "PlaybookType",
|
||||
"type": "string"
|
||||
|
||||
@@ -8,6 +8,9 @@
|
||||
"3CX Supply Chain Attack Network Indicators",
|
||||
"3cx_ioc_domains",
|
||||
"7zip CommandLine To SMB Share Path",
|
||||
"AD LDAP Account Locking",
|
||||
"AD LDAP Account Unlocking",
|
||||
"AD LDAP Entity Attribute Lookup",
|
||||
"AMOS Stealer",
|
||||
"APT29 Diplomatic Deceptions with WINELOADER",
|
||||
"APT37 Rustonotto and FadeStealer",
|
||||
@@ -123,6 +126,7 @@
|
||||
"AWS Detect Users creating keys with encrypt policy without MFA",
|
||||
"AWS Detect Users with KMS keys performing encryption S3",
|
||||
"AWS Disable Bucket Versioning",
|
||||
"AWS Disable User Accounts",
|
||||
"AWS EC2 Snapshot Shared Externally",
|
||||
"AWS ECR Container Scanning Findings High",
|
||||
"AWS ECR Container Scanning Findings Low Informational Unknown",
|
||||
@@ -135,9 +139,12 @@
|
||||
"AWS Exfiltration via Bucket Replication",
|
||||
"AWS Exfiltration via DataSync Task",
|
||||
"AWS Exfiltration via EC2 Snapshot",
|
||||
"AWS Find Inactive Users",
|
||||
"AWS High Number Of Failed Authentications For User",
|
||||
"AWS High Number Of Failed Authentications From Ip",
|
||||
"AWS IAM AccessDenied Discovery Events",
|
||||
"AWS IAM Account Locking",
|
||||
"AWS IAM Account Unlocking",
|
||||
"AWS IAM Assume Role Policy Brute Force",
|
||||
"AWS IAM Delete Policy",
|
||||
"AWS IAM Failure Group Deletion",
|
||||
@@ -154,6 +161,7 @@
|
||||
"AWS New MFA Method Registered For User",
|
||||
"AWS Password Policy Changes",
|
||||
"AWS S3 Bucket Security Monitoring",
|
||||
"AWS S3 Exfiltration Behavior Identified",
|
||||
"AWS SAML Update identity provider",
|
||||
"AWS Security Hub",
|
||||
"AWS Security Hub Alerts",
|
||||
@@ -168,12 +176,17 @@
|
||||
"Access to Vulnerable Ivanti Connect Secure Bookmark Endpoint",
|
||||
"AcidPour",
|
||||
"AcidRain",
|
||||
"Active Directory Disable Account Dispatch",
|
||||
"Active Directory Discovery",
|
||||
"Active Directory Enable Account Dispatch",
|
||||
"Active Directory Kerberos Attacks",
|
||||
"Active Directory Lateral Movement",
|
||||
"Active Directory Lateral Movement Identified",
|
||||
"Active Directory Password Spraying",
|
||||
"Active Directory Privilege Escalation",
|
||||
"Active Directory Privilege Escalation Identified",
|
||||
"Active Setup Registry Autostart",
|
||||
"ActiveDirectory Reset password",
|
||||
"Add DefaultUser And Password In Registry",
|
||||
"Add or Set Windows Defender Exclusion",
|
||||
"Adobe ColdFusion Access Control Bypass",
|
||||
@@ -200,17 +213,25 @@
|
||||
"Atlassian Confluence Server and Data Center CVE-2022-26134",
|
||||
"Attacker Tools On Endpoint",
|
||||
"Attempt To Add Certificate To Untrusted Store",
|
||||
"Attribute Lookup Dispatch",
|
||||
"Auto Admin Logon Registry Entry",
|
||||
"Automated Enrichment",
|
||||
"AwfulShred",
|
||||
"Axios Supply Chain Post Compromise",
|
||||
"Azorult",
|
||||
"Azure AD Account Locking",
|
||||
"Azure AD Account Unlocking",
|
||||
"Azure AD Admin Consent Bypassed by Service Principal",
|
||||
"Azure AD Application Administrator Role Assigned",
|
||||
"Azure AD Authentication Failed During MFA Challenge",
|
||||
"Azure AD AzureHound UserAgent Detected",
|
||||
"Azure AD Block User Consent For Risky Apps Disabled",
|
||||
"Azure AD Concurrent Sessions From Different Ips",
|
||||
"Azure AD Device Code Authentication",
|
||||
"Azure AD External Guest User Invited",
|
||||
"Azure AD FullAccessAsApp Permission Assigned",
|
||||
"Azure AD Global Administrator Role Assigned",
|
||||
"Azure AD Graph User Attribute Lookup",
|
||||
"Azure AD High Number Of Failed Authentications For User",
|
||||
"Azure AD High Number Of Failed Authentications From Ip",
|
||||
"Azure AD Multi-Factor Authentication Disabled",
|
||||
@@ -228,12 +249,15 @@
|
||||
"Azure AD OAuth Application Consent Granted By User",
|
||||
"Azure AD PIM Role Assigned",
|
||||
"Azure AD PIM Role Assignment Activated",
|
||||
"Azure AD Privileged Authentication Administrator Role Assigned",
|
||||
"Azure AD Privileged Graph API Permission Assigned",
|
||||
"Azure AD Privileged Role Assigned",
|
||||
"Azure AD Privileged Role Assigned to Service Principal",
|
||||
"Azure AD Service Principal Authentication",
|
||||
"Azure AD Service Principal Created",
|
||||
"Azure AD Service Principal Enumeration",
|
||||
"Azure AD Service Principal New Client Credentials",
|
||||
"Azure AD Service Principal Owner Added",
|
||||
"Azure AD Service Principal Privilege Escalation",
|
||||
"Azure AD Successful Authentication From Different Ips",
|
||||
"Azure AD Successful PowerShell Authentication",
|
||||
@@ -242,6 +266,8 @@
|
||||
"Azure AD Unusual Number of Failed Authentications From Ip",
|
||||
"Azure AD User Consent Blocked for Risky Application",
|
||||
"Azure AD User Consent Denied for OAuth Application",
|
||||
"Azure AD User Enabled And Password Reset",
|
||||
"Azure AD User ImmutableId Attribute Updated",
|
||||
"Azure Active Directory",
|
||||
"Azure Active Directory Account Takeover",
|
||||
"Azure Active Directory Add app role assignment to service principal",
|
||||
@@ -283,7 +309,9 @@
|
||||
"Baseline Of Kubernetes Process Resource",
|
||||
"Baseline Of Kubernetes Process Resource Ratio",
|
||||
"Baseline Of Open S3 Bucket Decommissioning",
|
||||
"Baseline of Network ACL Activity by ARN",
|
||||
"Baseline of S3 Bucket deletion activity by ARN",
|
||||
"Baseline of Security Group Activity by ARN",
|
||||
"Baseline of blocked outbound traffic from AWS",
|
||||
"Batch File Write to System32",
|
||||
"Bcdedit Command Back To Normal Mode Boot",
|
||||
@@ -294,6 +322,7 @@
|
||||
"BlackMatter Ransomware",
|
||||
"BlackSuit Ransomware",
|
||||
"BlankGrabber Stealer",
|
||||
"Block Indicators",
|
||||
"Brand Monitoring",
|
||||
"Braodo Stealer",
|
||||
"Bro conn",
|
||||
@@ -408,6 +437,8 @@
|
||||
"Cisco Network Visibility Module Analytics",
|
||||
"Cisco Network Visibility Module Flow Data",
|
||||
"Cisco Network Visibility Module OSquery",
|
||||
"Cisco Privileged Account Creation with HTTP Command Execution",
|
||||
"Cisco Privileged Account Creation with Suspicious SSH Activity",
|
||||
"Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity",
|
||||
"Cisco SD-WAN - Low Frequency Rogue Peer",
|
||||
"Cisco SD-WAN - Peering Activity",
|
||||
@@ -457,6 +488,8 @@
|
||||
"Cisco Smart Install Port Discovery and Status",
|
||||
"Cisco Smart Install Remote Code Execution CVE-2018-0171",
|
||||
"Cisco TFTP Server Configuration for Data Exfiltration",
|
||||
"Cisco Umbrella DNS Denylisting",
|
||||
"CiscoTalosIntelligence Identifier Reputation Analysis",
|
||||
"Citrix ADC Exploitation CVE-2023-3519",
|
||||
"Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure",
|
||||
"Citrix ADC and Gateway Unauthorized Data Disclosure",
|
||||
@@ -507,6 +540,7 @@
|
||||
"Count of assets by category",
|
||||
"Create Remote Thread In Shell Application",
|
||||
"Create Remote Thread into LSASS",
|
||||
"Create a list of approved AWS service accounts",
|
||||
"Create or delete windows shares using net exe",
|
||||
"Creation of Shadow Copy",
|
||||
"Creation of Shadow Copy with wmic and powershell",
|
||||
@@ -517,10 +551,23 @@
|
||||
"Critical Alerts",
|
||||
"CrowdStrike Falcon Stream Alert",
|
||||
"CrowdStrike Falcon Stream Alerts",
|
||||
"CrowdStrike OAuth API Device Attribute Lookup",
|
||||
"CrowdStrike OAuth API Dynamic Analysis",
|
||||
"CrowdStrike OAuth API Endpoint Analysis",
|
||||
"CrowdStrike OAuth API Executable Denylisting",
|
||||
"CrowdStrike OAuth API File Collection",
|
||||
"CrowdStrike OAuth API File Eviction",
|
||||
"CrowdStrike OAuth API File Restore",
|
||||
"CrowdStrike OAuth API Get Device Info",
|
||||
"CrowdStrike OAuth API Identifier Activity Analysis",
|
||||
"CrowdStrike OAuth API Network Isolation",
|
||||
"CrowdStrike OAuth API Network Restore",
|
||||
"CrowdStrike OAuth API Process Termination",
|
||||
"CrowdStrike ProcessRollup2",
|
||||
"Crowdstrike Admin Weak Password Policy",
|
||||
"Crowdstrike Admin With Duplicate Password",
|
||||
"Crowdstrike High Identity Risk Severity",
|
||||
"Crowdstrike Malware Triage",
|
||||
"Crowdstrike Medium Identity Risk Severity",
|
||||
"Crowdstrike Medium Severity Alert",
|
||||
"Crowdstrike Multiple LOW Severity Alerts",
|
||||
@@ -538,10 +585,12 @@
|
||||
"DHS Report TA18-074A",
|
||||
"DLLHost with no Command Line Arguments with Network",
|
||||
"DNS Amplification Attacks",
|
||||
"DNS Denylisting Dispatch",
|
||||
"DNS Exfiltration Using Nslookup App",
|
||||
"DNS Hijacking",
|
||||
"DNS Kerberos Coercion",
|
||||
"DNS Query Length With High Standard Deviation",
|
||||
"DNSTwist Domain Names",
|
||||
"DSQuery Domain Discovery",
|
||||
"DarkCrystal RAT",
|
||||
"DarkGate Malware",
|
||||
@@ -552,6 +601,7 @@
|
||||
"Default Baseline",
|
||||
"Default EventBasedDetection",
|
||||
"Defense Evasion or Unauthorized Access Via SDDL Tampering",
|
||||
"Delete Detected Files",
|
||||
"Delete ShadowCopy With PowerShell",
|
||||
"Deleting Shadow Copies",
|
||||
"Deobfuscate-Decode Files or Information",
|
||||
@@ -578,12 +628,14 @@
|
||||
"Detect Excessive Account Lockouts From Endpoint",
|
||||
"Detect Excessive User Account Lockouts",
|
||||
"Detect Exchange Web Shell",
|
||||
"Detect F5 TMUI RCE CVE-2020-5902",
|
||||
"Detect GCP Storage access from a new IP",
|
||||
"Detect HTML Help Renamed",
|
||||
"Detect HTML Help Spawn Child Process",
|
||||
"Detect HTML Help URL in Command Line",
|
||||
"Detect HTML Help Using InfoTech Storage Handlers",
|
||||
"Detect IPv6 Network Infrastructure Threats",
|
||||
"Detect Large ICMP Traffic",
|
||||
"Detect MSHTA Url in Command Line",
|
||||
"Detect Mimikatz With PowerShell Script Block Logging",
|
||||
"Detect New Local Admin account",
|
||||
@@ -636,11 +688,17 @@
|
||||
"Detect Spike in S3 Bucket deletion",
|
||||
"Detect Spike in blocked Outbound Traffic from your AWS",
|
||||
"Detect Traffic Mirroring",
|
||||
"Detect Unauthorized Assets by MAC address",
|
||||
"Detect Use of cmd exe to Launch Script Interpreters",
|
||||
"Detect WMI Event Subscription Persistence",
|
||||
"Detect Web Access to Decommissioned S3 Bucket",
|
||||
"Detect Windows DNS SIGRed via Splunk Stream",
|
||||
"Detect Windows DNS SIGRed via Zeek",
|
||||
"Detect Zerologon Attack",
|
||||
"Detect Zerologon via Zeek",
|
||||
"Detect attackers scanning for vulnerable JBoss servers",
|
||||
"Detect hosts connecting to dynamic domain providers",
|
||||
"Detect malicious requests to exploit JBoss servers",
|
||||
"Detect mshta inline hta execution",
|
||||
"Detect mshta renamed",
|
||||
"Detection of tools built by NirSoft",
|
||||
@@ -675,6 +733,7 @@
|
||||
"Disabling SystemRestore In Registry",
|
||||
"Disabling Task Manager",
|
||||
"Disabling Windows Local Security Authority Defences via Registry",
|
||||
"Discover DNS records",
|
||||
"Disk Wiper",
|
||||
"Domain Account Discovery with Dsquery",
|
||||
"Domain Account Discovery with Wmic",
|
||||
@@ -689,6 +748,7 @@
|
||||
"Drop IcedID License dat",
|
||||
"Dump LSASS via comsvcs DLL",
|
||||
"Dump LSASS via procdump",
|
||||
"Dynamic Analysis Dispatch",
|
||||
"Dynamic DNS",
|
||||
"DynoWiper",
|
||||
"ESXi Account Modified",
|
||||
@@ -696,6 +756,7 @@
|
||||
"ESXi Bulk VM Termination",
|
||||
"ESXi Download Errors",
|
||||
"ESXi Encryption Settings Modified",
|
||||
"ESXi External Root Login Activity",
|
||||
"ESXi Firewall Disabled",
|
||||
"ESXi Lockdown Mode Disabled",
|
||||
"ESXi Loghost Config Tampering",
|
||||
@@ -719,6 +780,7 @@
|
||||
"Elevated Group Discovery With Wmic",
|
||||
"Elevated Group Discovery with PowerView",
|
||||
"Email Attachments With Lots Of Spaces",
|
||||
"Email Notification for Malware",
|
||||
"Email files written outside of the Outlook directory",
|
||||
"Email servers sending high volume traffic to hosts",
|
||||
"Emotet Malware DHS Report TA18-201A",
|
||||
@@ -766,11 +828,15 @@
|
||||
"Fsutil Zeroing File",
|
||||
"G Suite Drive",
|
||||
"G Suite Gmail",
|
||||
"G Suite for GMail Message Identifier Activity Analysis",
|
||||
"G Suite for Gmail Message Eviction",
|
||||
"G Suite for Gmail Search and Purge",
|
||||
"GCP Account Takeover",
|
||||
"GCP Authentication Failed During MFA Challenge",
|
||||
"GCP Cross Account Activity",
|
||||
"GCP Detect gcploit framework",
|
||||
"GCP Kubernetes cluster pod scan detection",
|
||||
"GCP Multi-Factor Authentication Disabled",
|
||||
"GCP Multiple Failed MFA Requests For User",
|
||||
"GCP Multiple Users Failing To Authenticate From Ip",
|
||||
"GCP Successful Single-Factor Authentication",
|
||||
@@ -880,6 +946,7 @@
|
||||
"High Process Termination Frequency",
|
||||
"High Volume of Bytes Out to Url",
|
||||
"Hosts receiving high volume of network traffic from email server",
|
||||
"Hunting",
|
||||
"Hunting 3CXDesktopApp Software",
|
||||
"Hunting for Log4Shell",
|
||||
"ICACLS Grant Command",
|
||||
@@ -887,6 +954,8 @@
|
||||
"Icacls Deny Command",
|
||||
"IcedID",
|
||||
"IcedID Exfiltrated Archived File Creation",
|
||||
"Identifier Activity Analysis Dispatch",
|
||||
"Identifier Reputation Analysis Dispatch",
|
||||
"Identify Systems Creating Remote Desktop Traffic",
|
||||
"Identify Systems Receiving Remote Desktop Traffic",
|
||||
"Identify Systems Using Remote Desktop",
|
||||
@@ -902,6 +971,13 @@
|
||||
"Interlock Rat",
|
||||
"Internal Horizontal Port Scan",
|
||||
"Internal Horizontal Port Scan NMAP Top 20",
|
||||
"Internal Host SSH Investigate",
|
||||
"Internal Host SSH Log4j Investigate",
|
||||
"Internal Host SSH Log4j Respond",
|
||||
"Internal Host Splunk Investigate log4j",
|
||||
"Internal Host WinRM Investigate",
|
||||
"Internal Host WinRM Log4j Investigate",
|
||||
"Internal Host WinRM log4j Respond",
|
||||
"Internal Vertical Port Scan",
|
||||
"Internal Vulnerability Scan",
|
||||
"Ivanti Connect Secure Command Injection Attempts",
|
||||
@@ -929,6 +1005,7 @@
|
||||
"JetBrains TeamCity RCE Attempt",
|
||||
"JetBrains TeamCity Unauthenticated RCE",
|
||||
"JetBrains TeamCity Vulnerabilities",
|
||||
"Jira Related Tickets Search",
|
||||
"Jscript Execution Using Cscript App",
|
||||
"Juniper JunOS Remote Code Execution",
|
||||
"Juniper Networks Remote Code Execution Exploit Detection",
|
||||
@@ -1111,6 +1188,7 @@
|
||||
"Linux OpenVPN Privilege Escalation",
|
||||
"Linux PHP Privilege Escalation",
|
||||
"Linux Persistence Techniques",
|
||||
"Linux Persistence and Privilege Escalation Risk Behavior",
|
||||
"Linux Possible Access Or Modification Of sshd Config File",
|
||||
"Linux Possible Access To Credential Files",
|
||||
"Linux Possible Access To Sudoers File",
|
||||
@@ -1151,14 +1229,18 @@
|
||||
"Linux c99 Privilege Escalation",
|
||||
"Linux pkexec Privilege Escalation",
|
||||
"Living Off The Land",
|
||||
"Living Off The Land Detection",
|
||||
"Loading Of Dynwrapx Module",
|
||||
"Local Account Discovery With Wmic",
|
||||
"Local LLM Framework DNS Query",
|
||||
"Local Privilege Escalation With KrbRelayUp",
|
||||
"LockBit Ransomware",
|
||||
"Log4Shell CVE-2021-44228",
|
||||
"Log4Shell CVE-2021-44228 Exploitation",
|
||||
"Log4Shell JNDI Payload Injection Attempt",
|
||||
"Log4Shell JNDI Payload Injection with Outbound Connection",
|
||||
"Log4j Investigate",
|
||||
"Log4j Respond",
|
||||
"Logon Script Event Trigger Execution",
|
||||
"Lokibot",
|
||||
"Lotus Blossom Chrysalis Backdoor",
|
||||
@@ -1185,6 +1267,11 @@
|
||||
"MOVEit Transfer Critical Vulnerability",
|
||||
"MS Defender ATP Alerts",
|
||||
"MS Exchange Mailbox Replication service writing Active Server Pages",
|
||||
"MS Graph for Office 365 Message Eviction",
|
||||
"MS Graph for Office 365 Message Identifier Activity Analysis",
|
||||
"MS Graph for Office 365 Message Restore",
|
||||
"MS Graph for Office 365 Search and Purge",
|
||||
"MS Graph for Office 365 Search and Restore",
|
||||
"MS Scripting Process Loading Ldap Module",
|
||||
"MS Scripting Process Loading WMI Module",
|
||||
"MS365 Defender Incident Alerts",
|
||||
@@ -1216,6 +1303,7 @@
|
||||
"Malicious PowerShell Process - Execution Policy Bypass",
|
||||
"Malicious PowerShell Process With Obfuscation Techniques",
|
||||
"Malicious Powershell Executed As A Service",
|
||||
"Malware Hunt and Contain",
|
||||
"Masquerading - Rename System Utilities",
|
||||
"Medusa Ransomware",
|
||||
"Medusa Rootkit",
|
||||
@@ -1239,7 +1327,9 @@
|
||||
"Mmc LOLBAS Execution Process Spawn",
|
||||
"Modification Of Wallpaper",
|
||||
"Modify ACL permission To Files Or Folder",
|
||||
"Monitor Email For Brand Abuse",
|
||||
"Monitor Registry Keys for Print Monitors",
|
||||
"Monitor Web Traffic For Brand Abuse",
|
||||
"Monitor for Updates",
|
||||
"MoonPeak",
|
||||
"Mshta spawning Rundll32 OR Regsvr32 Process",
|
||||
@@ -1286,6 +1376,8 @@
|
||||
"O365 Advanced Audit Disabled",
|
||||
"O365 Application Available To Other Tenants",
|
||||
"O365 Application Registration Owner Added",
|
||||
"O365 ApplicationImpersonation Role Assigned",
|
||||
"O365 BEC Email Hiding Rule Created",
|
||||
"O365 Block User Consent For Risky Apps Disabled",
|
||||
"O365 Bypass MFA via Trusted IP",
|
||||
"O365 Change user license.",
|
||||
@@ -1298,10 +1390,13 @@
|
||||
"O365 Disable MFA",
|
||||
"O365 Disable Strong Authentication.",
|
||||
"O365 Elevated Mailbox Permission Assigned",
|
||||
"O365 Email Access By Security Administrator",
|
||||
"O365 Email Hard Delete Excessive Volume",
|
||||
"O365 Email New Inbox Rule Created",
|
||||
"O365 Email Password and Payroll Compromise Behavior",
|
||||
"O365 Email Receive and Hard Delete Takeover Behavior",
|
||||
"O365 Email Reported By Admin Found Malicious",
|
||||
"O365 Email Reported By User Found Malicious",
|
||||
"O365 Email Security Feature Changed",
|
||||
"O365 Email Send Attachments Excessive Volume",
|
||||
"O365 Email Send and Hard Delete Exfiltration Behavior",
|
||||
@@ -1314,6 +1409,7 @@
|
||||
"O365 Exfiltration via File Access",
|
||||
"O365 Exfiltration via File Download",
|
||||
"O365 Exfiltration via File Sync Download",
|
||||
"O365 External Guest User Invited",
|
||||
"O365 External Identity Policy Changed",
|
||||
"O365 File Permissioned Application Consent Granted by User",
|
||||
"O365 FullAccessAsApp Permission Assigned",
|
||||
@@ -1344,8 +1440,11 @@
|
||||
"O365 OAuth App Mailbox Access via Graph API",
|
||||
"O365 PST export alert",
|
||||
"O365 Privileged Graph API Permission Assigned",
|
||||
"O365 Privileged Role Assigned",
|
||||
"O365 Privileged Role Assigned To Service Principal",
|
||||
"O365 Safe Links Detection",
|
||||
"O365 Security And Compliance Alert Triggered",
|
||||
"O365 Service Principal New Client Credentials",
|
||||
"O365 Service Principal Privilege Escalation",
|
||||
"O365 Set Company Information.",
|
||||
"O365 Set-Mailbox",
|
||||
@@ -1384,6 +1483,7 @@
|
||||
"Okta New Device Enrolled on Account",
|
||||
"Okta Non-Standard VPN Usage",
|
||||
"Okta Phishing Detection with FastPass Origin Check",
|
||||
"Okta Risk Threshold Exceeded",
|
||||
"Okta Successful Single Factor Authentication",
|
||||
"Okta Suspicious Activity Reported",
|
||||
"Okta Suspicious Use of a Session Cookie",
|
||||
@@ -1410,6 +1510,7 @@
|
||||
"PXA Stealer",
|
||||
"Palo Alto Network Threat",
|
||||
"Palo Alto Network Traffic",
|
||||
"Panorama Outbound Traffic Filtering",
|
||||
"PaperCut MF NG Vulnerability",
|
||||
"PaperCut NG Remote Web Access Attempt",
|
||||
"PaperCut NG Suspicious Behavior Debug Log",
|
||||
@@ -1419,6 +1520,7 @@
|
||||
"PetitPotam Network Share Access Request",
|
||||
"PetitPotam Suspicious Kerberos TGT Request",
|
||||
"Phemedrone Stealer",
|
||||
"PhishTank URL Reputation Analysis",
|
||||
"Ping Sleep Batch Command",
|
||||
"PingID",
|
||||
"PingID Mismatch Auth Source and Verification Response",
|
||||
@@ -1488,6 +1590,7 @@
|
||||
"Previously Seen Zoom Child Processes - Initial",
|
||||
"Previously Seen Zoom Child Processes - Update",
|
||||
"Previously seen S3 bucket access by remote IP",
|
||||
"Previously seen command line arguments",
|
||||
"Print Processor Registry Autostart",
|
||||
"Print Spooler Adding A Printer Driver",
|
||||
"Print Spooler Failed to Load a Plug-in",
|
||||
@@ -1499,12 +1602,15 @@
|
||||
"Process Writing DynamicWrapperX",
|
||||
"Processes Tapping Keyboard Events",
|
||||
"Processes launching netsh",
|
||||
"Prohibited Network Traffic Allowed",
|
||||
"Prohibited Traffic Allowed or Protocol Mismatch",
|
||||
"PromptFlux",
|
||||
"PromptLock",
|
||||
"Protocol or Port Mismatch",
|
||||
"Protocols passing authentication in cleartext",
|
||||
"ProxyNotShell",
|
||||
"ProxyShell",
|
||||
"ProxyShell ProxyNotShell Behavior Detected",
|
||||
"Qakbot",
|
||||
"Quasar RAT",
|
||||
"QuietVault",
|
||||
@@ -1513,6 +1619,7 @@
|
||||
"Randomly Generated Windows Service Name",
|
||||
"Ransomware",
|
||||
"Ransomware Cloud",
|
||||
"Ransomware Investigate and Contain",
|
||||
"Ransomware Notes bulk creation",
|
||||
"React2Shell",
|
||||
"Recon AVProduct Through Pwh or WMI",
|
||||
@@ -1525,6 +1632,7 @@
|
||||
"Registry Keys for Creating SHIM Databases",
|
||||
"Regsvr32 Silent and Install Param Dll Loading",
|
||||
"Regsvr32 with Known Silent Switch Cmdline",
|
||||
"Related Tickets Search Dispatch",
|
||||
"Remcos",
|
||||
"Remcos RAT File Creation in Remcos Folder",
|
||||
"Remcos client registry install entry",
|
||||
@@ -1550,6 +1658,17 @@
|
||||
"Revil Ransomware",
|
||||
"Revil Registry Entry",
|
||||
"Rhysida Ransomware",
|
||||
"Risk Notable Block Indicators",
|
||||
"Risk Notable Enrich",
|
||||
"Risk Notable Import Data",
|
||||
"Risk Notable Investigate",
|
||||
"Risk Notable Merge Events",
|
||||
"Risk Notable Mitigate",
|
||||
"Risk Notable Preprocess",
|
||||
"Risk Notable Protect Assets and Users",
|
||||
"Risk Notable Review Indicators",
|
||||
"Risk Notable Verdict",
|
||||
"Risk Rule for Dev Sec Ops by Repository",
|
||||
"Router and Infrastructure Security",
|
||||
"Rubeus Command Line Parameters",
|
||||
"Rubeus Kerberos Ticket Exports Through Winlogon Access",
|
||||
@@ -1570,6 +1689,7 @@
|
||||
"SAM Database File Access Attempt",
|
||||
"SAP NetWeaver Exploitation",
|
||||
"SAP NetWeaver Visual Composer Exploitation Attempt",
|
||||
"SLUI RunAs Elevated",
|
||||
"SLUI Spawning a Process",
|
||||
"SMB Traffic Spike",
|
||||
"SQL Injection",
|
||||
@@ -1602,6 +1722,7 @@
|
||||
"Secret Blizzard",
|
||||
"SecretDumps Offline NTDS Dumping Tool",
|
||||
"Security Solution Tampering",
|
||||
"ServiceNow Related Tickets Search",
|
||||
"ServicePrincipalNames Discovery with PowerShell",
|
||||
"ServicePrincipalNames Discovery with SetSPN",
|
||||
"Services Escalate Exe",
|
||||
@@ -1629,7 +1750,12 @@
|
||||
"Splunk",
|
||||
"Splunk AppDynamics Secure Application Alert",
|
||||
"Splunk AppDynamics Secure Application Alerts",
|
||||
"Splunk Attack Analyzer Dynamic Analysis",
|
||||
"Splunk Automated Email Investigation",
|
||||
"Splunk Common Information Model (CIM)",
|
||||
"Splunk Identifier Activity Analysis",
|
||||
"Splunk Message Identifier Activity Analysis",
|
||||
"Splunk Notable Related Tickets Search",
|
||||
"Splunk Stream HTTP",
|
||||
"Splunk Stream IP",
|
||||
"Splunk Stream TCP",
|
||||
@@ -1641,6 +1767,8 @@
|
||||
"Spring4Shell CVE-2022-22965",
|
||||
"Spring4Shell Payload URL Request",
|
||||
"Sqlite Module In Temp Folder",
|
||||
"Start Investigation",
|
||||
"Steal or Forge Authentication Certificates Behavior Identified",
|
||||
"StealC Stealer",
|
||||
"Storm-0501 Ransomware",
|
||||
"Storm-2460 CLFS Zero Day Exploitation",
|
||||
@@ -1747,16 +1875,19 @@
|
||||
"Termite Ransomware",
|
||||
"Text4Shell CVE-2022-42889",
|
||||
"Threat Activity by Snort IDs",
|
||||
"Threat Intel Investigate",
|
||||
"Time Provider Persistence Registry",
|
||||
"Tomcat Session Deserialization Attempt",
|
||||
"Tomcat Session File Upload Attempt",
|
||||
"Trickbot",
|
||||
"Trickbot Named Pipe",
|
||||
"TruSTAR Enrich Indicators",
|
||||
"Trusted Developer Utilities Proxy Execution",
|
||||
"Trusted Developer Utilities Proxy Execution MSBuild",
|
||||
"Tuoni",
|
||||
"UAC Bypass MMC Load Unsigned Dll",
|
||||
"UAC Bypass With Colorui COM Object",
|
||||
"URL Outbound Traffic Filtering Dispatch",
|
||||
"USN Journal Deletion",
|
||||
"Uninstall App Using MsiExec",
|
||||
"Unknown Process Using The Kerberos Protocol",
|
||||
@@ -1768,6 +1899,7 @@
|
||||
"Unusual Processes",
|
||||
"Unusually Long Command Line",
|
||||
"Unusually Long Content-Type Length",
|
||||
"UrlScan IO Dynamic Analysis",
|
||||
"Use of Cleartext Protocols",
|
||||
"User Discovery With Env Vars PowerShell",
|
||||
"User Discovery With Env Vars PowerShell Script Block",
|
||||
@@ -1783,6 +1915,8 @@
|
||||
"VanHelsing Ransomware",
|
||||
"Vbscript Execution Using Wscript App",
|
||||
"Verclsid CLSID Execution",
|
||||
"VirusTotal V3 Dynamic Analysis",
|
||||
"VirusTotal v3 Identifier Reputation Analysis",
|
||||
"Void Manticore",
|
||||
"VoidLink Cloud-Native Linux Malware",
|
||||
"Volt Typhoon",
|
||||
@@ -1817,13 +1951,24 @@
|
||||
"WinRM Spawning a Process",
|
||||
"Windows .Key File Creation in Root Directory",
|
||||
"Windows AD Abnormal Object Access Activity",
|
||||
"Windows AD AdminSDHolder ACL Modified",
|
||||
"Windows AD Cross Domain SID History Addition",
|
||||
"Windows AD DCShadow Privileges ACL Addition",
|
||||
"Windows AD DSRM Account Changes",
|
||||
"Windows AD DSRM Password Reset",
|
||||
"Windows AD Dangerous Deny ACL Modification",
|
||||
"Windows AD Dangerous Group ACL Modification",
|
||||
"Windows AD Dangerous User ACL Modification",
|
||||
"Windows AD Domain Controller Audit Policy Disabled",
|
||||
"Windows AD Domain Controller Promotion",
|
||||
"Windows AD Domain Replication ACL Addition",
|
||||
"Windows AD Domain Root ACL Deletion",
|
||||
"Windows AD Domain Root ACL Modification",
|
||||
"Windows AD GPO Deleted",
|
||||
"Windows AD GPO Disabled",
|
||||
"Windows AD GPO New CSE Addition",
|
||||
"Windows AD Hidden OU Creation",
|
||||
"Windows AD Object Owner Updated",
|
||||
"Windows AD Privileged Account SID History Addition",
|
||||
"Windows AD Privileged Group Modification",
|
||||
"Windows AD Privileged Object Access Activity",
|
||||
@@ -1832,7 +1977,9 @@
|
||||
"Windows AD Replication Service Traffic",
|
||||
"Windows AD Rogue Domain Controller Network Activity",
|
||||
"Windows AD SID History Attribute Modified",
|
||||
"Windows AD Same Domain SID History Addition",
|
||||
"Windows AD Self DACL Assignment",
|
||||
"Windows AD ServicePrincipalName Added To Domain Account",
|
||||
"Windows AD Short Lived Domain Account ServicePrincipalName",
|
||||
"Windows AD Short Lived Domain Controller SPN Attribute",
|
||||
"Windows AD Short Lived Server Object",
|
||||
@@ -1905,6 +2052,7 @@
|
||||
"Windows Bypass UAC via Pkgmgr Tool",
|
||||
"Windows CAB File on Disk",
|
||||
"Windows COM Hijacking InprocServer32 Modification",
|
||||
"Windows Cabinet File Extraction Via Expand",
|
||||
"Windows Cached Domain Credentials Reg Query",
|
||||
"Windows Certificate Services",
|
||||
"Windows Certutil Root Certificate Addition",
|
||||
@@ -1930,6 +2078,7 @@
|
||||
"Windows Command Shell DCRat ForkBomb Payload",
|
||||
"Windows Command and Scripting Interpreter Hunting Path Traversal",
|
||||
"Windows Command and Scripting Interpreter Path Traversal Exec",
|
||||
"Windows Common Abused Cmd Shell Risk Behavior",
|
||||
"Windows Compatibility Telemetry Suspicious Child Process",
|
||||
"Windows Compatibility Telemetry Tampering Through Registry",
|
||||
"Windows Computer Account Changed to Domain Controller",
|
||||
@@ -1985,6 +2134,7 @@
|
||||
"Windows Defender ASR Rule Disabled",
|
||||
"Windows Defender ASR Rules Stacking",
|
||||
"Windows Defender ASR or Threat Configuration Tamper",
|
||||
"Windows Defender ATP Identifier Activity Analysis",
|
||||
"Windows Defender Alerts",
|
||||
"Windows Defender Exclusion Registry Entry",
|
||||
"Windows Defense Evasion Tactics",
|
||||
@@ -2305,6 +2455,7 @@
|
||||
"Windows Modify Registry ProxyServer",
|
||||
"Windows Modify Registry Qakbot Binary Data Registry",
|
||||
"Windows Modify Registry Regedit Silent Reg Import",
|
||||
"Windows Modify Registry Risk Behavior",
|
||||
"Windows Modify Registry Suppress Win Defender Notif",
|
||||
"Windows Modify Registry Tamper Protection",
|
||||
"Windows Modify Registry USeWuServer",
|
||||
@@ -2386,6 +2537,7 @@
|
||||
"Windows Phishing PDF File Executes URL Link",
|
||||
"Windows Phishing Recent ISO Exec Registry",
|
||||
"Windows Possible Credential Dumping",
|
||||
"Windows Post Exploitation Risk Behavior",
|
||||
"Windows Post-Exploitation",
|
||||
"Windows Potato Privilege Escalation Tool Execution",
|
||||
"Windows Potential AppDomainManager Hijack Artifacts Creation",
|
||||
@@ -2425,6 +2577,7 @@
|
||||
"Windows Private Keys Discovery",
|
||||
"Windows Privilege Escalation",
|
||||
"Windows Privilege Escalation Attempt Via MSI Rollback",
|
||||
"Windows Privilege Escalation Suspicious Process Elevation",
|
||||
"Windows Privilege Escalation System Process Without System Parent",
|
||||
"Windows Privilege Escalation User Process Spawn System Process",
|
||||
"Windows Privileged Group Modification",
|
||||
@@ -2511,8 +2664,10 @@
|
||||
"Windows SIP WinVerifyTrust Failed Trust Validation",
|
||||
"Windows SOAPHound Binary Execution",
|
||||
"Windows SQL Server Configuration Option Hunt",
|
||||
"Windows SQL Server Critical Procedures Enabled",
|
||||
"Windows SQL Server Extended Procedure DLL Loading Hunt",
|
||||
"Windows SQL Server Startup Procedure",
|
||||
"Windows SQL Server xp_cmdshell Config Change",
|
||||
"Windows SQL Spawning CertUtil",
|
||||
"Windows SQLCMD Execution",
|
||||
"Windows SSH Proxy Command",
|
||||
@@ -2573,6 +2728,7 @@
|
||||
"Windows SqlWriter SQLDumper DLL Sideload",
|
||||
"Windows Sqlservr Spawning Shell",
|
||||
"Windows Steal Authentication Certificates - ESC1 Abuse",
|
||||
"Windows Steal Authentication Certificates - ESC1 Authentication",
|
||||
"Windows Steal Authentication Certificates CS Backup",
|
||||
"Windows Steal Authentication Certificates CertUtil Backup",
|
||||
"Windows Steal Authentication Certificates Certificate Issued",
|
||||
@@ -2688,6 +2844,7 @@
|
||||
"XorDDos",
|
||||
"ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day",
|
||||
"ZOVWiper",
|
||||
"ZScaler Outbound Traffic Filtering",
|
||||
"Zeek Conn",
|
||||
"Zeek x509 Certificate with Punycode",
|
||||
"Zoom High Video Latency",
|
||||
|
||||
Reference in New Issue
Block a user