mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating src files
This commit is contained in:
@@ -48,7 +48,7 @@ data_models =
|
||||
description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it.
|
||||
id = 2e8948a5-5239-406b-b56b-6c50ff268af4
|
||||
version = 2.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration", "Persistence"], "cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["DE.DP", "DE.AE", "DE.CM", "PR.AC"]}
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration", "Persistence"], "cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["DE.CM", "DE.AE", "DE.DP", "PR.AC"]}
|
||||
modification_date = 2018-05-21
|
||||
reference = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"]
|
||||
providing_technologies = ["AWS", "Splunk Enterprise Security"]
|
||||
@@ -199,7 +199,7 @@ category = Malware
|
||||
creation_date = 2019-01-29
|
||||
data_models = ["Alerts", "Authentication", "Network_Traffic", "Risk", "Vulnerabilities", "Web"]
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more.
|
||||
id = ad7eb6e0-f06c-4781-b145-a42bd59c56e9
|
||||
id = bd91a2bc-d20b-4f44-a982-1bea98e86390
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Execution", "Collection", "Persistence"], "cis20": ["CIS 4", "CIS 8"], "kill_chain_phases": ["Command and Control", "Installation"], "nist": ["DE.CM", "DE.DP", "PR.PT"]}
|
||||
modification_date = 2019-01-29
|
||||
@@ -221,7 +221,7 @@ data_models = ["Application_State", "Authentication", "Endpoint", "Network_Traff
|
||||
description = Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data.
|
||||
id = 8e03c61e-13c4-4dcd-bfbe-5ce5a8dc031a
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Commonly Used Port", "Data Staged", "Email Collection", "Collection"], "cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM"]}
|
||||
mappings = {"mitre_attack": ["Commonly Used Port", "Data Staged", "Email Collection", "Collection"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 7", "CIS 8"], "nist": ["PR.PT", "DE.AE", "DE.CM"]}
|
||||
modification_date = 2018-11-02
|
||||
reference = ["https://attack.mitre.org/wiki/Collection", "https://attack.mitre.org/wiki/Technique/T1074"]
|
||||
providing_technologies = ["Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
@@ -698,7 +698,7 @@ data_models = ["Application_State", "Authentication", "Network_Resolution", "Net
|
||||
description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers.
|
||||
id = 6d13121c-90f3-446d-8ac3-27efbbc65218
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Delivery", "Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Defense Evasion"], "cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Command and Control", "Actions on Objectives", "Delivery"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.DS"]}
|
||||
modification_date = 2018-07-24
|
||||
reference = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"]
|
||||
providing_technologies = ["Bluecoat", "Bro", "Linux", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "macOS"]
|
||||
@@ -898,7 +898,7 @@ data_models =
|
||||
description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required.
|
||||
id = 2e8948a5-5239-406b-b56b-6c50w3168af3
|
||||
version = 2.0
|
||||
mappings = {"mitre_attack": ["Exfiltration", "Credential Access", "Execution", "Initial Access"], "cis20": ["CIS 13", "CIS 14"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["DE.CM", "PR.DS", "DE.DP", "PR.AC"]}
|
||||
mappings = {"mitre_attack": ["Exfiltration", "Credential Access", "Execution", "Initial Access"], "cis20": ["CIS 13", "CIS 14"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["DE.DP", "PR.DS", "DE.CM", "PR.AC"]}
|
||||
modification_date = 2018-11-27
|
||||
reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"]
|
||||
providing_technologies = ["AWS", "Splunk Enterprise Security"]
|
||||
@@ -1039,7 +1039,7 @@ data_models = ["Application_State", "Authentication", "Change_Analysis", "Endpoi
|
||||
description = Monitor and detect registry changes initiated from remote locations, which can be a sign that an attacker has infiltrated your system.
|
||||
id = 2b1800dd-92f9-47dd-a981-fdf1351e5d55
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Modify Registry", "Local Port Monitor", "Application Shimming", "Lateral Movement", "Authentication Package", "Registry Run Keys / Start Folder", "AppInit DLLs", "Privilege Escalation", "Defense Evasion", "Accessibility Features", "Change Default File Association", "Persistence"], "cis20": ["CIS 5", "CIS 3", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.IP"]}
|
||||
mappings = {"mitre_attack": ["Modify Registry", "Local Port Monitor", "Authentication Package", "Lateral Movement", "Application Shimming", "Registry Run Keys / Start Folder", "AppInit DLLs", "Privilege Escalation", "Defense Evasion", "Accessibility Features", "Change Default File Association", "Persistence"], "cis20": ["CIS 5", "CIS 3", "CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["PR.PT", "DE.AE", "DE.CM", "PR.AC", "PR.IP"]}
|
||||
modification_date = 2018-12-03
|
||||
reference = ["https://redcanary.com/blog/windows-registry-attacks-threat-detection/", "https://attack.mitre.org/wiki/Technique/T1112"]
|
||||
providing_technologies = ["Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Splunk Enterprise Security", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
|
||||
+574
-574
File diff suppressed because it is too large
Load Diff
+1934
-1934
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user