Add updated schemas, which has been updated as manual_review content was resolved

This commit is contained in:
Eric McGinnis
2026-05-20 12:19:45 -07:00
parent 0c869bfc93
commit 1fb3da73f2
3 changed files with 171 additions and 1 deletions
+12
View File
@@ -133,7 +133,9 @@
"Baseline Of Kubernetes Process Resource",
"Baseline Of Kubernetes Process Resource Ratio",
"Baseline Of Open S3 Bucket Decommissioning",
"Baseline of Network ACL Activity by ARN",
"Baseline of S3 Bucket deletion activity by ARN",
"Baseline of Security Group Activity by ARN",
"Baseline of blocked outbound traffic from AWS",
"BishopFox Sliver Adversary Emulation Framework",
"Black Basta Ransomware",
@@ -216,6 +218,7 @@
"ConnectWise ScreenConnect Vulnerabilities",
"Count of Unique IPs Connecting to Ports",
"Count of assets by category",
"Create a list of approved AWS service accounts",
"Credential Dumping",
"Critical Alerts",
"CrowdStrike Falcon Stream Alert",
@@ -227,6 +230,7 @@
"DHS Report TA18-074A",
"DNS Amplification Attacks",
"DNS Hijacking",
"DNSTwist Domain Names",
"DarkCrystal RAT",
"DarkGate Malware",
"DarkSide Ransomware",
@@ -241,6 +245,7 @@
"Detect Zerologon Attack",
"Dev Sec Ops",
"Disabling Security Tools",
"Discover DNS records",
"Disk Wiper",
"Domain Trust Discovery",
"Double Zero Destructor",
@@ -439,6 +444,7 @@
"Previously Seen Zoom Child Processes - Initial",
"Previously Seen Zoom Child Processes - Update",
"Previously seen S3 bucket access by remote IP",
"Previously seen command line arguments",
"PrintNightmare CVE-2021-34527",
"Prohibited Traffic Allowed or Protocol Mismatch",
"PromptFlux",
@@ -2892,10 +2898,15 @@
"Baseline Of Kubernetes Process Resource",
"Baseline Of Kubernetes Process Resource Ratio",
"Baseline Of Open S3 Bucket Decommissioning",
"Baseline of Network ACL Activity by ARN",
"Baseline of S3 Bucket deletion activity by ARN",
"Baseline of Security Group Activity by ARN",
"Baseline of blocked outbound traffic from AWS",
"Count of Unique IPs Connecting to Ports",
"Count of assets by category",
"Create a list of approved AWS service accounts",
"DNSTwist Domain Names",
"Discover DNS records",
"Identify Systems Creating Remote Desktop Traffic",
"Identify Systems Receiving Remote Desktop Traffic",
"Identify Systems Using Remote Desktop",
@@ -2920,6 +2931,7 @@
"Previously Seen Zoom Child Processes - Initial",
"Previously Seen Zoom Child Processes - Update",
"Previously seen S3 bucket access by remote IP",
"Previously seen command line arguments",
"Windows Updates Install Failures",
"Windows Updates Install Successes"
],
+2 -1
View File
@@ -2361,7 +2361,8 @@
"description": "PlayBook Type field.\n\nThis is intentionally different than the Type Enum\nabove due to legacy naming in the playbook files.",
"enum": [
"Automation",
"Input"
"Input",
"Enterprise Security"
],
"title": "PlaybookType",
"type": "string"
+157
View File
@@ -8,6 +8,9 @@
"3CX Supply Chain Attack Network Indicators",
"3cx_ioc_domains",
"7zip CommandLine To SMB Share Path",
"AD LDAP Account Locking",
"AD LDAP Account Unlocking",
"AD LDAP Entity Attribute Lookup",
"AMOS Stealer",
"APT29 Diplomatic Deceptions with WINELOADER",
"APT37 Rustonotto and FadeStealer",
@@ -123,6 +126,7 @@
"AWS Detect Users creating keys with encrypt policy without MFA",
"AWS Detect Users with KMS keys performing encryption S3",
"AWS Disable Bucket Versioning",
"AWS Disable User Accounts",
"AWS EC2 Snapshot Shared Externally",
"AWS ECR Container Scanning Findings High",
"AWS ECR Container Scanning Findings Low Informational Unknown",
@@ -135,9 +139,12 @@
"AWS Exfiltration via Bucket Replication",
"AWS Exfiltration via DataSync Task",
"AWS Exfiltration via EC2 Snapshot",
"AWS Find Inactive Users",
"AWS High Number Of Failed Authentications For User",
"AWS High Number Of Failed Authentications From Ip",
"AWS IAM AccessDenied Discovery Events",
"AWS IAM Account Locking",
"AWS IAM Account Unlocking",
"AWS IAM Assume Role Policy Brute Force",
"AWS IAM Delete Policy",
"AWS IAM Failure Group Deletion",
@@ -154,6 +161,7 @@
"AWS New MFA Method Registered For User",
"AWS Password Policy Changes",
"AWS S3 Bucket Security Monitoring",
"AWS S3 Exfiltration Behavior Identified",
"AWS SAML Update identity provider",
"AWS Security Hub",
"AWS Security Hub Alerts",
@@ -168,12 +176,17 @@
"Access to Vulnerable Ivanti Connect Secure Bookmark Endpoint",
"AcidPour",
"AcidRain",
"Active Directory Disable Account Dispatch",
"Active Directory Discovery",
"Active Directory Enable Account Dispatch",
"Active Directory Kerberos Attacks",
"Active Directory Lateral Movement",
"Active Directory Lateral Movement Identified",
"Active Directory Password Spraying",
"Active Directory Privilege Escalation",
"Active Directory Privilege Escalation Identified",
"Active Setup Registry Autostart",
"ActiveDirectory Reset password",
"Add DefaultUser And Password In Registry",
"Add or Set Windows Defender Exclusion",
"Adobe ColdFusion Access Control Bypass",
@@ -200,17 +213,25 @@
"Atlassian Confluence Server and Data Center CVE-2022-26134",
"Attacker Tools On Endpoint",
"Attempt To Add Certificate To Untrusted Store",
"Attribute Lookup Dispatch",
"Auto Admin Logon Registry Entry",
"Automated Enrichment",
"AwfulShred",
"Axios Supply Chain Post Compromise",
"Azorult",
"Azure AD Account Locking",
"Azure AD Account Unlocking",
"Azure AD Admin Consent Bypassed by Service Principal",
"Azure AD Application Administrator Role Assigned",
"Azure AD Authentication Failed During MFA Challenge",
"Azure AD AzureHound UserAgent Detected",
"Azure AD Block User Consent For Risky Apps Disabled",
"Azure AD Concurrent Sessions From Different Ips",
"Azure AD Device Code Authentication",
"Azure AD External Guest User Invited",
"Azure AD FullAccessAsApp Permission Assigned",
"Azure AD Global Administrator Role Assigned",
"Azure AD Graph User Attribute Lookup",
"Azure AD High Number Of Failed Authentications For User",
"Azure AD High Number Of Failed Authentications From Ip",
"Azure AD Multi-Factor Authentication Disabled",
@@ -228,12 +249,15 @@
"Azure AD OAuth Application Consent Granted By User",
"Azure AD PIM Role Assigned",
"Azure AD PIM Role Assignment Activated",
"Azure AD Privileged Authentication Administrator Role Assigned",
"Azure AD Privileged Graph API Permission Assigned",
"Azure AD Privileged Role Assigned",
"Azure AD Privileged Role Assigned to Service Principal",
"Azure AD Service Principal Authentication",
"Azure AD Service Principal Created",
"Azure AD Service Principal Enumeration",
"Azure AD Service Principal New Client Credentials",
"Azure AD Service Principal Owner Added",
"Azure AD Service Principal Privilege Escalation",
"Azure AD Successful Authentication From Different Ips",
"Azure AD Successful PowerShell Authentication",
@@ -242,6 +266,8 @@
"Azure AD Unusual Number of Failed Authentications From Ip",
"Azure AD User Consent Blocked for Risky Application",
"Azure AD User Consent Denied for OAuth Application",
"Azure AD User Enabled And Password Reset",
"Azure AD User ImmutableId Attribute Updated",
"Azure Active Directory",
"Azure Active Directory Account Takeover",
"Azure Active Directory Add app role assignment to service principal",
@@ -283,7 +309,9 @@
"Baseline Of Kubernetes Process Resource",
"Baseline Of Kubernetes Process Resource Ratio",
"Baseline Of Open S3 Bucket Decommissioning",
"Baseline of Network ACL Activity by ARN",
"Baseline of S3 Bucket deletion activity by ARN",
"Baseline of Security Group Activity by ARN",
"Baseline of blocked outbound traffic from AWS",
"Batch File Write to System32",
"Bcdedit Command Back To Normal Mode Boot",
@@ -294,6 +322,7 @@
"BlackMatter Ransomware",
"BlackSuit Ransomware",
"BlankGrabber Stealer",
"Block Indicators",
"Brand Monitoring",
"Braodo Stealer",
"Bro conn",
@@ -408,6 +437,8 @@
"Cisco Network Visibility Module Analytics",
"Cisco Network Visibility Module Flow Data",
"Cisco Network Visibility Module OSquery",
"Cisco Privileged Account Creation with HTTP Command Execution",
"Cisco Privileged Account Creation with Suspicious SSH Activity",
"Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity",
"Cisco SD-WAN - Low Frequency Rogue Peer",
"Cisco SD-WAN - Peering Activity",
@@ -457,6 +488,8 @@
"Cisco Smart Install Port Discovery and Status",
"Cisco Smart Install Remote Code Execution CVE-2018-0171",
"Cisco TFTP Server Configuration for Data Exfiltration",
"Cisco Umbrella DNS Denylisting",
"CiscoTalosIntelligence Identifier Reputation Analysis",
"Citrix ADC Exploitation CVE-2023-3519",
"Citrix ADC and Gateway CitrixBleed 2 Memory Disclosure",
"Citrix ADC and Gateway Unauthorized Data Disclosure",
@@ -507,6 +540,7 @@
"Count of assets by category",
"Create Remote Thread In Shell Application",
"Create Remote Thread into LSASS",
"Create a list of approved AWS service accounts",
"Create or delete windows shares using net exe",
"Creation of Shadow Copy",
"Creation of Shadow Copy with wmic and powershell",
@@ -517,10 +551,23 @@
"Critical Alerts",
"CrowdStrike Falcon Stream Alert",
"CrowdStrike Falcon Stream Alerts",
"CrowdStrike OAuth API Device Attribute Lookup",
"CrowdStrike OAuth API Dynamic Analysis",
"CrowdStrike OAuth API Endpoint Analysis",
"CrowdStrike OAuth API Executable Denylisting",
"CrowdStrike OAuth API File Collection",
"CrowdStrike OAuth API File Eviction",
"CrowdStrike OAuth API File Restore",
"CrowdStrike OAuth API Get Device Info",
"CrowdStrike OAuth API Identifier Activity Analysis",
"CrowdStrike OAuth API Network Isolation",
"CrowdStrike OAuth API Network Restore",
"CrowdStrike OAuth API Process Termination",
"CrowdStrike ProcessRollup2",
"Crowdstrike Admin Weak Password Policy",
"Crowdstrike Admin With Duplicate Password",
"Crowdstrike High Identity Risk Severity",
"Crowdstrike Malware Triage",
"Crowdstrike Medium Identity Risk Severity",
"Crowdstrike Medium Severity Alert",
"Crowdstrike Multiple LOW Severity Alerts",
@@ -538,10 +585,12 @@
"DHS Report TA18-074A",
"DLLHost with no Command Line Arguments with Network",
"DNS Amplification Attacks",
"DNS Denylisting Dispatch",
"DNS Exfiltration Using Nslookup App",
"DNS Hijacking",
"DNS Kerberos Coercion",
"DNS Query Length With High Standard Deviation",
"DNSTwist Domain Names",
"DSQuery Domain Discovery",
"DarkCrystal RAT",
"DarkGate Malware",
@@ -552,6 +601,7 @@
"Default Baseline",
"Default EventBasedDetection",
"Defense Evasion or Unauthorized Access Via SDDL Tampering",
"Delete Detected Files",
"Delete ShadowCopy With PowerShell",
"Deleting Shadow Copies",
"Deobfuscate-Decode Files or Information",
@@ -578,12 +628,14 @@
"Detect Excessive Account Lockouts From Endpoint",
"Detect Excessive User Account Lockouts",
"Detect Exchange Web Shell",
"Detect F5 TMUI RCE CVE-2020-5902",
"Detect GCP Storage access from a new IP",
"Detect HTML Help Renamed",
"Detect HTML Help Spawn Child Process",
"Detect HTML Help URL in Command Line",
"Detect HTML Help Using InfoTech Storage Handlers",
"Detect IPv6 Network Infrastructure Threats",
"Detect Large ICMP Traffic",
"Detect MSHTA Url in Command Line",
"Detect Mimikatz With PowerShell Script Block Logging",
"Detect New Local Admin account",
@@ -636,11 +688,17 @@
"Detect Spike in S3 Bucket deletion",
"Detect Spike in blocked Outbound Traffic from your AWS",
"Detect Traffic Mirroring",
"Detect Unauthorized Assets by MAC address",
"Detect Use of cmd exe to Launch Script Interpreters",
"Detect WMI Event Subscription Persistence",
"Detect Web Access to Decommissioned S3 Bucket",
"Detect Windows DNS SIGRed via Splunk Stream",
"Detect Windows DNS SIGRed via Zeek",
"Detect Zerologon Attack",
"Detect Zerologon via Zeek",
"Detect attackers scanning for vulnerable JBoss servers",
"Detect hosts connecting to dynamic domain providers",
"Detect malicious requests to exploit JBoss servers",
"Detect mshta inline hta execution",
"Detect mshta renamed",
"Detection of tools built by NirSoft",
@@ -675,6 +733,7 @@
"Disabling SystemRestore In Registry",
"Disabling Task Manager",
"Disabling Windows Local Security Authority Defences via Registry",
"Discover DNS records",
"Disk Wiper",
"Domain Account Discovery with Dsquery",
"Domain Account Discovery with Wmic",
@@ -689,6 +748,7 @@
"Drop IcedID License dat",
"Dump LSASS via comsvcs DLL",
"Dump LSASS via procdump",
"Dynamic Analysis Dispatch",
"Dynamic DNS",
"DynoWiper",
"ESXi Account Modified",
@@ -696,6 +756,7 @@
"ESXi Bulk VM Termination",
"ESXi Download Errors",
"ESXi Encryption Settings Modified",
"ESXi External Root Login Activity",
"ESXi Firewall Disabled",
"ESXi Lockdown Mode Disabled",
"ESXi Loghost Config Tampering",
@@ -719,6 +780,7 @@
"Elevated Group Discovery With Wmic",
"Elevated Group Discovery with PowerView",
"Email Attachments With Lots Of Spaces",
"Email Notification for Malware",
"Email files written outside of the Outlook directory",
"Email servers sending high volume traffic to hosts",
"Emotet Malware DHS Report TA18-201A",
@@ -766,11 +828,15 @@
"Fsutil Zeroing File",
"G Suite Drive",
"G Suite Gmail",
"G Suite for GMail Message Identifier Activity Analysis",
"G Suite for Gmail Message Eviction",
"G Suite for Gmail Search and Purge",
"GCP Account Takeover",
"GCP Authentication Failed During MFA Challenge",
"GCP Cross Account Activity",
"GCP Detect gcploit framework",
"GCP Kubernetes cluster pod scan detection",
"GCP Multi-Factor Authentication Disabled",
"GCP Multiple Failed MFA Requests For User",
"GCP Multiple Users Failing To Authenticate From Ip",
"GCP Successful Single-Factor Authentication",
@@ -880,6 +946,7 @@
"High Process Termination Frequency",
"High Volume of Bytes Out to Url",
"Hosts receiving high volume of network traffic from email server",
"Hunting",
"Hunting 3CXDesktopApp Software",
"Hunting for Log4Shell",
"ICACLS Grant Command",
@@ -887,6 +954,8 @@
"Icacls Deny Command",
"IcedID",
"IcedID Exfiltrated Archived File Creation",
"Identifier Activity Analysis Dispatch",
"Identifier Reputation Analysis Dispatch",
"Identify Systems Creating Remote Desktop Traffic",
"Identify Systems Receiving Remote Desktop Traffic",
"Identify Systems Using Remote Desktop",
@@ -902,6 +971,13 @@
"Interlock Rat",
"Internal Horizontal Port Scan",
"Internal Horizontal Port Scan NMAP Top 20",
"Internal Host SSH Investigate",
"Internal Host SSH Log4j Investigate",
"Internal Host SSH Log4j Respond",
"Internal Host Splunk Investigate log4j",
"Internal Host WinRM Investigate",
"Internal Host WinRM Log4j Investigate",
"Internal Host WinRM log4j Respond",
"Internal Vertical Port Scan",
"Internal Vulnerability Scan",
"Ivanti Connect Secure Command Injection Attempts",
@@ -929,6 +1005,7 @@
"JetBrains TeamCity RCE Attempt",
"JetBrains TeamCity Unauthenticated RCE",
"JetBrains TeamCity Vulnerabilities",
"Jira Related Tickets Search",
"Jscript Execution Using Cscript App",
"Juniper JunOS Remote Code Execution",
"Juniper Networks Remote Code Execution Exploit Detection",
@@ -1111,6 +1188,7 @@
"Linux OpenVPN Privilege Escalation",
"Linux PHP Privilege Escalation",
"Linux Persistence Techniques",
"Linux Persistence and Privilege Escalation Risk Behavior",
"Linux Possible Access Or Modification Of sshd Config File",
"Linux Possible Access To Credential Files",
"Linux Possible Access To Sudoers File",
@@ -1151,14 +1229,18 @@
"Linux c99 Privilege Escalation",
"Linux pkexec Privilege Escalation",
"Living Off The Land",
"Living Off The Land Detection",
"Loading Of Dynwrapx Module",
"Local Account Discovery With Wmic",
"Local LLM Framework DNS Query",
"Local Privilege Escalation With KrbRelayUp",
"LockBit Ransomware",
"Log4Shell CVE-2021-44228",
"Log4Shell CVE-2021-44228 Exploitation",
"Log4Shell JNDI Payload Injection Attempt",
"Log4Shell JNDI Payload Injection with Outbound Connection",
"Log4j Investigate",
"Log4j Respond",
"Logon Script Event Trigger Execution",
"Lokibot",
"Lotus Blossom Chrysalis Backdoor",
@@ -1185,6 +1267,11 @@
"MOVEit Transfer Critical Vulnerability",
"MS Defender ATP Alerts",
"MS Exchange Mailbox Replication service writing Active Server Pages",
"MS Graph for Office 365 Message Eviction",
"MS Graph for Office 365 Message Identifier Activity Analysis",
"MS Graph for Office 365 Message Restore",
"MS Graph for Office 365 Search and Purge",
"MS Graph for Office 365 Search and Restore",
"MS Scripting Process Loading Ldap Module",
"MS Scripting Process Loading WMI Module",
"MS365 Defender Incident Alerts",
@@ -1216,6 +1303,7 @@
"Malicious PowerShell Process - Execution Policy Bypass",
"Malicious PowerShell Process With Obfuscation Techniques",
"Malicious Powershell Executed As A Service",
"Malware Hunt and Contain",
"Masquerading - Rename System Utilities",
"Medusa Ransomware",
"Medusa Rootkit",
@@ -1239,7 +1327,9 @@
"Mmc LOLBAS Execution Process Spawn",
"Modification Of Wallpaper",
"Modify ACL permission To Files Or Folder",
"Monitor Email For Brand Abuse",
"Monitor Registry Keys for Print Monitors",
"Monitor Web Traffic For Brand Abuse",
"Monitor for Updates",
"MoonPeak",
"Mshta spawning Rundll32 OR Regsvr32 Process",
@@ -1286,6 +1376,8 @@
"O365 Advanced Audit Disabled",
"O365 Application Available To Other Tenants",
"O365 Application Registration Owner Added",
"O365 ApplicationImpersonation Role Assigned",
"O365 BEC Email Hiding Rule Created",
"O365 Block User Consent For Risky Apps Disabled",
"O365 Bypass MFA via Trusted IP",
"O365 Change user license.",
@@ -1298,10 +1390,13 @@
"O365 Disable MFA",
"O365 Disable Strong Authentication.",
"O365 Elevated Mailbox Permission Assigned",
"O365 Email Access By Security Administrator",
"O365 Email Hard Delete Excessive Volume",
"O365 Email New Inbox Rule Created",
"O365 Email Password and Payroll Compromise Behavior",
"O365 Email Receive and Hard Delete Takeover Behavior",
"O365 Email Reported By Admin Found Malicious",
"O365 Email Reported By User Found Malicious",
"O365 Email Security Feature Changed",
"O365 Email Send Attachments Excessive Volume",
"O365 Email Send and Hard Delete Exfiltration Behavior",
@@ -1314,6 +1409,7 @@
"O365 Exfiltration via File Access",
"O365 Exfiltration via File Download",
"O365 Exfiltration via File Sync Download",
"O365 External Guest User Invited",
"O365 External Identity Policy Changed",
"O365 File Permissioned Application Consent Granted by User",
"O365 FullAccessAsApp Permission Assigned",
@@ -1344,8 +1440,11 @@
"O365 OAuth App Mailbox Access via Graph API",
"O365 PST export alert",
"O365 Privileged Graph API Permission Assigned",
"O365 Privileged Role Assigned",
"O365 Privileged Role Assigned To Service Principal",
"O365 Safe Links Detection",
"O365 Security And Compliance Alert Triggered",
"O365 Service Principal New Client Credentials",
"O365 Service Principal Privilege Escalation",
"O365 Set Company Information.",
"O365 Set-Mailbox",
@@ -1384,6 +1483,7 @@
"Okta New Device Enrolled on Account",
"Okta Non-Standard VPN Usage",
"Okta Phishing Detection with FastPass Origin Check",
"Okta Risk Threshold Exceeded",
"Okta Successful Single Factor Authentication",
"Okta Suspicious Activity Reported",
"Okta Suspicious Use of a Session Cookie",
@@ -1410,6 +1510,7 @@
"PXA Stealer",
"Palo Alto Network Threat",
"Palo Alto Network Traffic",
"Panorama Outbound Traffic Filtering",
"PaperCut MF NG Vulnerability",
"PaperCut NG Remote Web Access Attempt",
"PaperCut NG Suspicious Behavior Debug Log",
@@ -1419,6 +1520,7 @@
"PetitPotam Network Share Access Request",
"PetitPotam Suspicious Kerberos TGT Request",
"Phemedrone Stealer",
"PhishTank URL Reputation Analysis",
"Ping Sleep Batch Command",
"PingID",
"PingID Mismatch Auth Source and Verification Response",
@@ -1488,6 +1590,7 @@
"Previously Seen Zoom Child Processes - Initial",
"Previously Seen Zoom Child Processes - Update",
"Previously seen S3 bucket access by remote IP",
"Previously seen command line arguments",
"Print Processor Registry Autostart",
"Print Spooler Adding A Printer Driver",
"Print Spooler Failed to Load a Plug-in",
@@ -1499,12 +1602,15 @@
"Process Writing DynamicWrapperX",
"Processes Tapping Keyboard Events",
"Processes launching netsh",
"Prohibited Network Traffic Allowed",
"Prohibited Traffic Allowed or Protocol Mismatch",
"PromptFlux",
"PromptLock",
"Protocol or Port Mismatch",
"Protocols passing authentication in cleartext",
"ProxyNotShell",
"ProxyShell",
"ProxyShell ProxyNotShell Behavior Detected",
"Qakbot",
"Quasar RAT",
"QuietVault",
@@ -1513,6 +1619,7 @@
"Randomly Generated Windows Service Name",
"Ransomware",
"Ransomware Cloud",
"Ransomware Investigate and Contain",
"Ransomware Notes bulk creation",
"React2Shell",
"Recon AVProduct Through Pwh or WMI",
@@ -1525,6 +1632,7 @@
"Registry Keys for Creating SHIM Databases",
"Regsvr32 Silent and Install Param Dll Loading",
"Regsvr32 with Known Silent Switch Cmdline",
"Related Tickets Search Dispatch",
"Remcos",
"Remcos RAT File Creation in Remcos Folder",
"Remcos client registry install entry",
@@ -1550,6 +1658,17 @@
"Revil Ransomware",
"Revil Registry Entry",
"Rhysida Ransomware",
"Risk Notable Block Indicators",
"Risk Notable Enrich",
"Risk Notable Import Data",
"Risk Notable Investigate",
"Risk Notable Merge Events",
"Risk Notable Mitigate",
"Risk Notable Preprocess",
"Risk Notable Protect Assets and Users",
"Risk Notable Review Indicators",
"Risk Notable Verdict",
"Risk Rule for Dev Sec Ops by Repository",
"Router and Infrastructure Security",
"Rubeus Command Line Parameters",
"Rubeus Kerberos Ticket Exports Through Winlogon Access",
@@ -1570,6 +1689,7 @@
"SAM Database File Access Attempt",
"SAP NetWeaver Exploitation",
"SAP NetWeaver Visual Composer Exploitation Attempt",
"SLUI RunAs Elevated",
"SLUI Spawning a Process",
"SMB Traffic Spike",
"SQL Injection",
@@ -1602,6 +1722,7 @@
"Secret Blizzard",
"SecretDumps Offline NTDS Dumping Tool",
"Security Solution Tampering",
"ServiceNow Related Tickets Search",
"ServicePrincipalNames Discovery with PowerShell",
"ServicePrincipalNames Discovery with SetSPN",
"Services Escalate Exe",
@@ -1629,7 +1750,12 @@
"Splunk",
"Splunk AppDynamics Secure Application Alert",
"Splunk AppDynamics Secure Application Alerts",
"Splunk Attack Analyzer Dynamic Analysis",
"Splunk Automated Email Investigation",
"Splunk Common Information Model (CIM)",
"Splunk Identifier Activity Analysis",
"Splunk Message Identifier Activity Analysis",
"Splunk Notable Related Tickets Search",
"Splunk Stream HTTP",
"Splunk Stream IP",
"Splunk Stream TCP",
@@ -1641,6 +1767,8 @@
"Spring4Shell CVE-2022-22965",
"Spring4Shell Payload URL Request",
"Sqlite Module In Temp Folder",
"Start Investigation",
"Steal or Forge Authentication Certificates Behavior Identified",
"StealC Stealer",
"Storm-0501 Ransomware",
"Storm-2460 CLFS Zero Day Exploitation",
@@ -1747,16 +1875,19 @@
"Termite Ransomware",
"Text4Shell CVE-2022-42889",
"Threat Activity by Snort IDs",
"Threat Intel Investigate",
"Time Provider Persistence Registry",
"Tomcat Session Deserialization Attempt",
"Tomcat Session File Upload Attempt",
"Trickbot",
"Trickbot Named Pipe",
"TruSTAR Enrich Indicators",
"Trusted Developer Utilities Proxy Execution",
"Trusted Developer Utilities Proxy Execution MSBuild",
"Tuoni",
"UAC Bypass MMC Load Unsigned Dll",
"UAC Bypass With Colorui COM Object",
"URL Outbound Traffic Filtering Dispatch",
"USN Journal Deletion",
"Uninstall App Using MsiExec",
"Unknown Process Using The Kerberos Protocol",
@@ -1768,6 +1899,7 @@
"Unusual Processes",
"Unusually Long Command Line",
"Unusually Long Content-Type Length",
"UrlScan IO Dynamic Analysis",
"Use of Cleartext Protocols",
"User Discovery With Env Vars PowerShell",
"User Discovery With Env Vars PowerShell Script Block",
@@ -1783,6 +1915,8 @@
"VanHelsing Ransomware",
"Vbscript Execution Using Wscript App",
"Verclsid CLSID Execution",
"VirusTotal V3 Dynamic Analysis",
"VirusTotal v3 Identifier Reputation Analysis",
"Void Manticore",
"VoidLink Cloud-Native Linux Malware",
"Volt Typhoon",
@@ -1817,13 +1951,24 @@
"WinRM Spawning a Process",
"Windows .Key File Creation in Root Directory",
"Windows AD Abnormal Object Access Activity",
"Windows AD AdminSDHolder ACL Modified",
"Windows AD Cross Domain SID History Addition",
"Windows AD DCShadow Privileges ACL Addition",
"Windows AD DSRM Account Changes",
"Windows AD DSRM Password Reset",
"Windows AD Dangerous Deny ACL Modification",
"Windows AD Dangerous Group ACL Modification",
"Windows AD Dangerous User ACL Modification",
"Windows AD Domain Controller Audit Policy Disabled",
"Windows AD Domain Controller Promotion",
"Windows AD Domain Replication ACL Addition",
"Windows AD Domain Root ACL Deletion",
"Windows AD Domain Root ACL Modification",
"Windows AD GPO Deleted",
"Windows AD GPO Disabled",
"Windows AD GPO New CSE Addition",
"Windows AD Hidden OU Creation",
"Windows AD Object Owner Updated",
"Windows AD Privileged Account SID History Addition",
"Windows AD Privileged Group Modification",
"Windows AD Privileged Object Access Activity",
@@ -1832,7 +1977,9 @@
"Windows AD Replication Service Traffic",
"Windows AD Rogue Domain Controller Network Activity",
"Windows AD SID History Attribute Modified",
"Windows AD Same Domain SID History Addition",
"Windows AD Self DACL Assignment",
"Windows AD ServicePrincipalName Added To Domain Account",
"Windows AD Short Lived Domain Account ServicePrincipalName",
"Windows AD Short Lived Domain Controller SPN Attribute",
"Windows AD Short Lived Server Object",
@@ -1905,6 +2052,7 @@
"Windows Bypass UAC via Pkgmgr Tool",
"Windows CAB File on Disk",
"Windows COM Hijacking InprocServer32 Modification",
"Windows Cabinet File Extraction Via Expand",
"Windows Cached Domain Credentials Reg Query",
"Windows Certificate Services",
"Windows Certutil Root Certificate Addition",
@@ -1930,6 +2078,7 @@
"Windows Command Shell DCRat ForkBomb Payload",
"Windows Command and Scripting Interpreter Hunting Path Traversal",
"Windows Command and Scripting Interpreter Path Traversal Exec",
"Windows Common Abused Cmd Shell Risk Behavior",
"Windows Compatibility Telemetry Suspicious Child Process",
"Windows Compatibility Telemetry Tampering Through Registry",
"Windows Computer Account Changed to Domain Controller",
@@ -1985,6 +2134,7 @@
"Windows Defender ASR Rule Disabled",
"Windows Defender ASR Rules Stacking",
"Windows Defender ASR or Threat Configuration Tamper",
"Windows Defender ATP Identifier Activity Analysis",
"Windows Defender Alerts",
"Windows Defender Exclusion Registry Entry",
"Windows Defense Evasion Tactics",
@@ -2305,6 +2455,7 @@
"Windows Modify Registry ProxyServer",
"Windows Modify Registry Qakbot Binary Data Registry",
"Windows Modify Registry Regedit Silent Reg Import",
"Windows Modify Registry Risk Behavior",
"Windows Modify Registry Suppress Win Defender Notif",
"Windows Modify Registry Tamper Protection",
"Windows Modify Registry USeWuServer",
@@ -2386,6 +2537,7 @@
"Windows Phishing PDF File Executes URL Link",
"Windows Phishing Recent ISO Exec Registry",
"Windows Possible Credential Dumping",
"Windows Post Exploitation Risk Behavior",
"Windows Post-Exploitation",
"Windows Potato Privilege Escalation Tool Execution",
"Windows Potential AppDomainManager Hijack Artifacts Creation",
@@ -2425,6 +2577,7 @@
"Windows Private Keys Discovery",
"Windows Privilege Escalation",
"Windows Privilege Escalation Attempt Via MSI Rollback",
"Windows Privilege Escalation Suspicious Process Elevation",
"Windows Privilege Escalation System Process Without System Parent",
"Windows Privilege Escalation User Process Spawn System Process",
"Windows Privileged Group Modification",
@@ -2511,8 +2664,10 @@
"Windows SIP WinVerifyTrust Failed Trust Validation",
"Windows SOAPHound Binary Execution",
"Windows SQL Server Configuration Option Hunt",
"Windows SQL Server Critical Procedures Enabled",
"Windows SQL Server Extended Procedure DLL Loading Hunt",
"Windows SQL Server Startup Procedure",
"Windows SQL Server xp_cmdshell Config Change",
"Windows SQL Spawning CertUtil",
"Windows SQLCMD Execution",
"Windows SSH Proxy Command",
@@ -2573,6 +2728,7 @@
"Windows SqlWriter SQLDumper DLL Sideload",
"Windows Sqlservr Spawning Shell",
"Windows Steal Authentication Certificates - ESC1 Abuse",
"Windows Steal Authentication Certificates - ESC1 Authentication",
"Windows Steal Authentication Certificates CS Backup",
"Windows Steal Authentication Certificates CertUtil Backup",
"Windows Steal Authentication Certificates Certificate Issued",
@@ -2688,6 +2844,7 @@
"XorDDos",
"ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day",
"ZOVWiper",
"ZScaler Outbound Traffic Filtering",
"Zeek Conn",
"Zeek x509 Certificate with Punycode",
"Zoom High Video Latency",