updating src files

This commit is contained in:
research bot
2019-02-06 21:51:52 +00:00
parent af84f3c1c1
commit 1fcad4d628
3 changed files with 2514 additions and 2514 deletions
+6 -6
View File
@@ -48,7 +48,7 @@ data_models =
description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it.
id = 2e8948a5-5239-406b-b56b-6c50ff268af4
version = 2.0
mappings = {"mitre_attack": ["Command and Control", "Exfiltration", "Persistence"], "cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["DE.DP", "DE.AE", "DE.CM", "PR.AC"]}
mappings = {"mitre_attack": ["Command and Control", "Exfiltration", "Persistence"], "cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["DE.CM", "DE.AE", "DE.DP", "PR.AC"]}
modification_date = 2018-05-21
reference = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"]
providing_technologies = ["AWS", "Splunk Enterprise Security"]
@@ -199,7 +199,7 @@ category = Malware
creation_date = 2019-01-29
data_models = ["Alerts", "Authentication", "Network_Traffic", "Risk", "Vulnerabilities", "Web"]
description = Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more.
id = ad7eb6e0-f06c-4781-b145-a42bd59c56e9
id = bd91a2bc-d20b-4f44-a982-1bea98e86390
version = 1.0
mappings = {"mitre_attack": ["Command and Control", "Execution", "Collection", "Persistence"], "cis20": ["CIS 4", "CIS 8"], "kill_chain_phases": ["Command and Control", "Installation"], "nist": ["DE.CM", "DE.DP", "PR.PT"]}
modification_date = 2019-01-29
@@ -221,7 +221,7 @@ data_models = ["Application_State", "Authentication", "Endpoint", "Network_Traff
description = Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data.
id = 8e03c61e-13c4-4dcd-bfbe-5ce5a8dc031a
version = 1.0
mappings = {"mitre_attack": ["Commonly Used Port", "Data Staged", "Email Collection", "Collection"], "cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM"]}
mappings = {"mitre_attack": ["Commonly Used Port", "Data Staged", "Email Collection", "Collection"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 7", "CIS 8"], "nist": ["PR.PT", "DE.AE", "DE.CM"]}
modification_date = 2018-11-02
reference = ["https://attack.mitre.org/wiki/Collection", "https://attack.mitre.org/wiki/Technique/T1074"]
providing_technologies = ["Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
@@ -698,7 +698,7 @@ data_models = ["Application_State", "Authentication", "Network_Resolution", "Net
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
id = 6d13121c-90f3-446d-8ac3-27efbbc65218
version = 1.0
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Delivery", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Actions on Objectives", "Delivery"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
modification_date = 2018-07-24
reference = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
providing_technologies = ["Bluecoat", "Bro", "Linux", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "macOS"]
@@ -898,7 +898,7 @@ data_models =
description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required.
id = 2e8948a5-5239-406b-b56b-6c50w3168af3
version = 2.0
mappings = {"mitre_attack": ["Exfiltration", "Credential Access", "Execution", "Initial Access"], "cis20": ["CIS 13", "CIS 14"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["DE.CM", "PR.DS", "DE.DP", "PR.AC"]}
mappings = {"mitre_attack": ["Exfiltration", "Credential Access", "Execution", "Initial Access"], "cis20": ["CIS 13", "CIS 14"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["DE.DP", "PR.DS", "DE.CM", "PR.AC"]}
modification_date = 2018-11-27
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"]
providing_technologies = ["AWS", "Splunk Enterprise Security"]
@@ -1039,7 +1039,7 @@ data_models = ["Application_State", "Authentication", "Change_Analysis", "Endpoi
description = Monitor and detect registry changes initiated from remote locations, which can be a sign that an attacker has infiltrated your system.
id = 2b1800dd-92f9-47dd-a981-fdf1351e5d55
version = 1.0
mappings = {"mitre_attack": ["Modify Registry", "Local Port Monitor", "Application Shimming", "Lateral Movement", "Authentication Package", "Registry Run Keys / Start Folder", "AppInit DLLs", "Privilege Escalation", "Defense Evasion", "Accessibility Features", "Change Default File Association", "Persistence"], "cis20": ["CIS 5", "CIS 3", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.IP"]}
mappings = {"mitre_attack": ["Modify Registry", "Local Port Monitor", "Authentication Package", "Lateral Movement", "Application Shimming", "Registry Run Keys / Start Folder", "AppInit DLLs", "Privilege Escalation", "Defense Evasion", "Accessibility Features", "Change Default File Association", "Persistence"], "cis20": ["CIS 5", "CIS 3", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.IP"]}
modification_date = 2018-12-03
reference = ["https://redcanary.com/blog/windows-registry-attacks-threat-detection/", "https://attack.mitre.org/wiki/Technique/T1112"]
providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Splunk Enterprise Security", "Sysmon", "Tanium", "Ziften", "macOS"]
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff