mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into jp_paranoid
This commit is contained in:
@@ -45,7 +45,7 @@ jobs:
|
||||
git fetch origin pull/${{ github.event.pull_request.number }}/head:new_branch_for_testing
|
||||
#We must specifically get the PR's target branch from security_content, not the one that resides in the fork PR's forked repo
|
||||
git switch new_branch_for_testing
|
||||
contentctl test --disable-tqdm --no-enable-integration-testing --container-settings.num-containers 2 --post-test-behavior never_pause mode:changes --mode.target-branch ${{ github.base_ref }}
|
||||
contentctl test --verbose --disable-tqdm --no-enable-integration-testing --container-settings.num-containers 2 --post-test-behavior never_pause mode:changes --mode.target-branch ${{ github.base_ref }}
|
||||
echo "contentctl test - COMPLETED"
|
||||
continue-on-error: true
|
||||
|
||||
|
||||
@@ -69,5 +69,14 @@ fields:
|
||||
- vendor_product
|
||||
- version
|
||||
- vpcflow_action
|
||||
output_fields:
|
||||
- action
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- transport
|
||||
example_log: 2 123397614277 eni-0b0f9f261f45e6489 10.0.1.30 10.0.1.1 47254 22 17 2
|
||||
98 1697608042 1697608070 ACCEPT OK
|
||||
|
||||
@@ -99,6 +99,27 @@ fields:
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- original_file_name
|
||||
- parent_process
|
||||
- parent_process_exec
|
||||
- parent_process_guid
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Processes
|
||||
|
||||
@@ -17,3 +17,7 @@ supported_TA:
|
||||
- name: Splunk Add-on for Okta Identity Cloud
|
||||
url: https://splunkbase.splunk.com/app/6553
|
||||
version: 3.0.0
|
||||
output_fields:
|
||||
- dest
|
||||
- src
|
||||
- user
|
||||
@@ -27,6 +27,13 @@ field_mappings:
|
||||
url: Web.url
|
||||
url_length: Web.url_length
|
||||
src: Web.src
|
||||
output_fields:
|
||||
- http_user_agent
|
||||
- http_method
|
||||
- url
|
||||
- url_length
|
||||
- src
|
||||
- dest
|
||||
fields:
|
||||
- _time
|
||||
- date_hour
|
||||
|
||||
@@ -36,6 +36,24 @@ fields:
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
output_fields:
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- dvc
|
||||
- protocol
|
||||
- protocol_version
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- transport
|
||||
- user
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: All_Traffic
|
||||
|
||||
@@ -73,6 +73,19 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
- Guid
|
||||
- Opcode
|
||||
- Name
|
||||
- Path
|
||||
- ProcessID
|
||||
- ScriptBlockId
|
||||
- ScriptBlockText
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Processes
|
||||
|
||||
@@ -117,6 +117,27 @@ fields:
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- original_file_name
|
||||
- parent_process
|
||||
- parent_process_exec
|
||||
- parent_process_guid
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Processes
|
||||
|
||||
@@ -98,6 +98,19 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- user_id
|
||||
- parent_process_name
|
||||
- parent_process_guid
|
||||
- process_name
|
||||
- process_guid
|
||||
- process_id
|
||||
- signature
|
||||
- SourceImage
|
||||
- TargetImage
|
||||
- GrantedAccess
|
||||
- CallTrace
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>10</EventID><Version>3</Version><Level>4</Level><Task>10</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-02-01T21:01:44.672666100Z'/><EventRecordID>150624412</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -92,6 +92,15 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- file_name
|
||||
- file_path
|
||||
- process_guid
|
||||
- process_id
|
||||
- user
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Filesystem
|
||||
|
||||
@@ -94,6 +94,17 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- process_guid
|
||||
- process_id
|
||||
- registry_hive
|
||||
- registry_path
|
||||
- registry_key_name
|
||||
- status
|
||||
- user
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Registry
|
||||
|
||||
@@ -101,6 +101,19 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- process_guid
|
||||
- process_id
|
||||
- registry_hive
|
||||
- registry_path
|
||||
- registry_key_name
|
||||
- registry_value_data
|
||||
- registry_value_name
|
||||
- status
|
||||
- user
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Registry
|
||||
|
||||
@@ -97,6 +97,21 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- dvc
|
||||
- file_hash
|
||||
- file_name
|
||||
- file_path
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>15</EventID><Version>2</Version><Level>4</Level><Task>15</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2021-04-28T20:11:34.709744300Z'/><EventRecordID>667860</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -85,6 +85,19 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- dvc
|
||||
- pipe_name
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>17</EventID><Version>1</Version><Level>4</Level><Task>17</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2021-04-19T21:00:18.288457000Z'/><EventRecordID>162168</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -89,6 +89,19 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- dvc
|
||||
- pipe_name
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>18</EventID><Version>1</Version><Level>4</Level><Task>18</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2021-04-19T21:00:19.312721800Z'/><EventRecordID>162173</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -91,6 +91,19 @@ fields:
|
||||
- user_id
|
||||
- user_name
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- dvc
|
||||
- object
|
||||
- object_category
|
||||
- object_path
|
||||
- signature
|
||||
- signature_id
|
||||
- src
|
||||
- status
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>20</EventID><Version>3</Version><Level>4</Level><Task>20</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2020-12-08T13:54:48.517698800Z'/><EventRecordID>6249</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -94,6 +94,20 @@ fields:
|
||||
- user_id
|
||||
- user_name
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- dvc
|
||||
- object
|
||||
- object_attrs
|
||||
- object_category
|
||||
- object_path
|
||||
- signature
|
||||
- signature_id
|
||||
- src
|
||||
- status
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>21</EventID><Version>3</Version><Level>4</Level><Task>21</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2021-06-16T21:46:50.225290200Z'/><EventRecordID>151644</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -95,6 +95,14 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- answer
|
||||
- answer_count
|
||||
- query
|
||||
- query_count
|
||||
- reply_code_id
|
||||
- src
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>22</EventID><Version>5</Version><Level>4</Level><Task>22</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2021-03-24T12:25:15.098978900Z'/><EventRecordID>113892</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -100,6 +100,24 @@ fields:
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- dvc
|
||||
- file_path
|
||||
- file_hash
|
||||
- file_name
|
||||
- file_modify_time
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>23</EventID><Version>5</Version><Level>4</Level><Task>23</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-02-01T10:57:09.815326000Z'/><EventRecordID>281771</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -14,4 +14,22 @@ supported_TA:
|
||||
version: 4.0.2
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- dvc
|
||||
- file_path
|
||||
- file_hash
|
||||
- file_name
|
||||
- file_modify_time
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: |-
|
||||
|
||||
@@ -114,6 +114,22 @@ fields:
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- app
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- direction
|
||||
- dvc
|
||||
- protocol
|
||||
- protocol_version
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- transport
|
||||
- user
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>3</EventID><Version>5</Version><Level>4</Level><Task>3</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-09-15T12:56:22.958249300Z'/><EventRecordID>156837</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -86,6 +86,18 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- process
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>5</EventID><Version>3</Version><Level>4</Level><Task>5</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2021-03-16T14:01:44.008858500Z'/><EventRecordID>39965</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -88,6 +88,15 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- dvc
|
||||
- process_hash
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>6</EventID><Version>4</Version><Level>4</Level><Task>6</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-04-04T17:37:04.643206900Z'/><EventRecordID>15708989</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -108,6 +108,24 @@ fields:
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- Image
|
||||
- ImageLoaded
|
||||
- dest
|
||||
- loaded_file
|
||||
- loaded_file_path
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- service_dll_signature_exists
|
||||
- service_dll_signature_verified
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>7</EventID><Version>3</Version><Level>4</Level><Task>7</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-09-12T08:06:31.445185300Z'/><EventRecordID>45273</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -100,6 +100,22 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- parent_process_exec
|
||||
- parent_process_guid
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>8</EventID><Version>2</Version><Level>4</Level><Task>8</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-10-27T13:59:12.440938600Z'/><EventRecordID>362233</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -87,6 +87,18 @@ fields:
|
||||
- timestartpos
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- dvc
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- signature
|
||||
- signature_id
|
||||
- user_id
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>9</EventID><Version>2</Version><Level>4</Level><Task>9</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-02-25T12:25:33.375618100Z'/><EventRecordID>190607</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -108,6 +108,27 @@ fields:
|
||||
- timestartpos
|
||||
- user
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- original_file_name
|
||||
- parent_process
|
||||
- parent_process_exec
|
||||
- parent_process_guid
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Processes
|
||||
|
||||
@@ -85,6 +85,21 @@ fields:
|
||||
- timestartpos
|
||||
- user
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- file_access_time
|
||||
- file_create_time
|
||||
- file_hash
|
||||
- file_modify_time
|
||||
- file_name
|
||||
- file_path
|
||||
- file_acl
|
||||
- file_size
|
||||
- process_guid
|
||||
- process_id
|
||||
- user
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Filesystem
|
||||
|
||||
@@ -68,6 +68,8 @@ fields:
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-IIS-W3SVC-WP' Guid='{670080D9-742A-4187-8D16-41143D1290BD}'
|
||||
EventSourceName='W3SVC-WP'/><EventID Qualifiers='49152'>2282</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated
|
||||
|
||||
@@ -63,6 +63,8 @@ fields:
|
||||
- timestamp
|
||||
- user_id
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-ProcessExitMonitor' Guid='{FD771D53-8492-4057-8E35-8C02813AF49B}'
|
||||
EventSourceName='Process Exit Monitor'/><EventID Qualifiers='16384'>3000</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated
|
||||
|
||||
@@ -77,6 +77,22 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- app
|
||||
- change_type
|
||||
- dest
|
||||
- dvc
|
||||
- name
|
||||
- object_attrs
|
||||
- object_category
|
||||
- service
|
||||
- service_name
|
||||
- signature
|
||||
- signature_id
|
||||
- status
|
||||
- subject
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Eventlog' Guid='{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'/><EventID>1100</EventID><Version>0</Version><Level>4</Level><Task>103</Task><Opcode>0</Opcode><Keywords>0x4020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-04-08T18:48:10.378485000Z'/><EventRecordID>140874</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -83,6 +83,22 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- app
|
||||
- change_type
|
||||
- dest
|
||||
- dvc
|
||||
- name
|
||||
- object_attrs
|
||||
- object_category
|
||||
- signature
|
||||
- signature_id
|
||||
- src_user
|
||||
- status
|
||||
- subject
|
||||
- user
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Eventlog' Guid='{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'/><EventID>1102</EventID><Version>0</Version><Level>4</Level><Task>104</Task><Opcode>0</Opcode><Keywords>0x4020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-03-05T09:18:29.313328400Z'/><EventRecordID>1826166</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -121,6 +121,15 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- app
|
||||
- authentication_method
|
||||
- dest
|
||||
- signature
|
||||
- signature_id
|
||||
- src
|
||||
- user
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4624</EventID><Version>2</Version><Level>0</Level><Task>12544</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-03-23T19:15:28.337312500Z'/><EventRecordID>371886</EventRecordID><Correlation
|
||||
|
||||
@@ -116,6 +116,15 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- app
|
||||
- authentication_method
|
||||
- dest
|
||||
- signature
|
||||
- signature_id
|
||||
- src
|
||||
- user
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4625</EventID><Version>0</Version><Level>0</Level><Task>12544</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-03-22T20:25:15.594676400Z'/><EventRecordID>367348</EventRecordID><Correlation
|
||||
|
||||
@@ -96,6 +96,13 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- app
|
||||
- dest
|
||||
- signature_id
|
||||
- user
|
||||
- vendor_product
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4627</EventID><Version>0</Version><Level>0</Level><Task>12554</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-10-05T20:02:43.026235200Z'/><EventRecordID>186260</EventRecordID><Correlation
|
||||
|
||||
@@ -109,6 +109,10 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
- src_ip
|
||||
- user
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4648</EventID><Version>0</Version><Level>0</Level><Task>12544</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-09-08T21:33:47.813673700Z'/><EventRecordID>336567</EventRecordID><Correlation
|
||||
|
||||
@@ -96,6 +96,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4662</EventID><Version>0</Version><Level>0</Level><Task>14080</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-02-02T22:41:45.751175400Z'/><EventRecordID>21623198276</EventRecordID><Correlation
|
||||
|
||||
@@ -101,6 +101,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4663</EventID><Version>1</Version><Level>0</Level><Task>12800</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-02-21T14:08:33.452364300Z'/><EventRecordID>10525869</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -86,6 +86,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4672</EventID><Version>0</Version><Level>0</Level><Task>12548</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-03-27T18:35:15.439521100Z'/><EventRecordID>148946</EventRecordID><Correlation
|
||||
|
||||
@@ -94,6 +94,27 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- original_file_name
|
||||
- parent_process
|
||||
- parent_process_exec
|
||||
- parent_process_guid
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Processes
|
||||
|
||||
@@ -88,4 +88,6 @@ fields:
|
||||
- user
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: 04/26/2022 11:12:09 AM
|
||||
|
||||
@@ -87,4 +87,6 @@ fields:
|
||||
- user
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: 11/12/2021 05:16:44 PM
|
||||
|
||||
@@ -104,6 +104,8 @@ fields:
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4703</EventID><Version>0</Version><Level>0</Level><Task>13317</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-08-31T09:47:43.137598500Z'/><EventRecordID>328761</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -91,6 +91,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4719</EventID><Version>0</Version><Level>0</Level><Task>13568</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-11-03T00:02:53.722907800Z'/><EventRecordID>353597</EventRecordID><Correlation
|
||||
|
||||
@@ -110,4 +110,6 @@ fields:
|
||||
- user_group_id
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: 10/09/2020 10:41:26 AM
|
||||
|
||||
@@ -100,6 +100,8 @@ fields:
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4724</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-02-21T18:02:22.774396900Z'/><EventRecordID>276779</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -99,6 +99,8 @@ fields:
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4725</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-02-21T19:20:19.727858200Z'/><EventRecordID>278771</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -100,6 +100,8 @@ fields:
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4726</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-02-21T19:38:47.481373400Z'/><EventRecordID>279283</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -13,5 +13,7 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4727</EventID><Version>0</Version><Level>0</Level><Task>13826</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime='2024-07-30T16:51:45.175123800Z'/><EventRecordID>183204880</EventRecordID><Correlation/><Execution ProcessID='672' ThreadID='3064'/><Channel>Security</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security/></System><EventData><Data Name='TargetUserName'>ESX Admins</Data><Data Name='TargetDomainName'>ATTACKRANGE</Data><Data Name='TargetSid'>ATTACKRANGE\ESX Admins</Data><Data Name='SubjectUserSid'>ATTACKRANGE\Administrator</Data><Data Name='SubjectUserName'>administrator</Data><Data Name='SubjectDomainName'>ATTACKRANGE</Data><Data Name='SubjectLogonId'>0xe32f0</Data><Data Name='PrivilegeList'>-</Data><Data Name='SamAccountName'>ESX Admins</Data><Data Name='SidHistory'>-</Data></EventData></Event>
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -99,5 +99,7 @@ fields:
|
||||
- _sourcetype
|
||||
- _subsecond
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4730</EventID><Version>0</Version><Level>0</Level><Task>13826</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime='2024-07-30T16:51:39.613057200Z'/><EventRecordID>183203591</EventRecordID><Correlation/><Execution ProcessID='672' ThreadID='2420'/><Channel>Security</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security/></System><EventData><Data Name='TargetUserName'>ESX Admins</Data><Data Name='TargetDomainName'>ATTACKRANGE</Data><Data Name='TargetSid'>S-1-5-21-560616516-1175754387-3922768235-4211</Data><Data Name='SubjectUserSid'>ATTACKRANGE\Administrator</Data><Data Name='SubjectUserName'>administrator</Data><Data Name='SubjectDomainName'>ATTACKRANGE</Data><Data Name='SubjectLogonId'>0xe32f0</Data><Data Name='PrivilegeList'>-</Data></EventData></Event>
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -99,4 +99,6 @@ fields:
|
||||
- vendor
|
||||
- vendor_privilege
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: 10/09/2020 10:41:26 AM
|
||||
|
||||
@@ -99,6 +99,8 @@ fields:
|
||||
- _sourcetype
|
||||
- _subsecond
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4737</EventID><Version>0</Version><Level>0</Level><Task>13826</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime='2024-07-30T16:50:34.812948700Z'/><EventRecordID>183186860</EventRecordID><Correlation/><Execution ProcessID='672' ThreadID='900'/><Channel>Security</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security/></System><EventData><Data Name='TargetUserName'>ESX Admins</Data><Data Name='TargetDomainName'>ATTACKRANGE</Data><Data Name='TargetSid'>S-1-5-21-560616516-1175754387-3922768235-4211</Data><Data Name='SubjectUserSid'>ATTACKRANGE\Administrator</Data><Data Name='SubjectUserName'>administrator</Data><Data Name='SubjectDomainName'>ATTACKRANGE</Data><Data Name='SubjectLogonId'>0xe32f0</Data><Data Name='PrivilegeList'>-</Data><Data Name='SamAccountName'>-</Data><Data Name='SidHistory'>-</Data></EventData></Event>
|
||||
|
||||
|
||||
@@ -120,6 +120,8 @@ fields:
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4738</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-11-17T03:25:57.674067800Z'/><EventRecordID>6389713</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -108,6 +108,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4739</EventID><Version>0</Version><Level>0</Level><Task>13569</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-02-02T00:37:16.161168500Z'/><EventRecordID>394176</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -121,6 +121,8 @@ fields:
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4741</EventID><Version>0</Version><Level>0</Level><Task>13825</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-04-08T18:48:04.618400500Z'/><EventRecordID>143475</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -121,6 +121,8 @@ fields:
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4742</EventID><Version>0</Version><Level>0</Level><Task>13825</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-08-04T09:26:26.793335600Z'/><EventRecordID>901860</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -102,6 +102,8 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4768</EventID><Version>0</Version><Level>0</Level><Task>14339</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-09-08T18:16:25.601071000Z'/><EventRecordID>391562</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -102,6 +102,8 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4769</EventID><Version>0</Version><Level>0</Level><Task>14337</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-04-09T01:00:49.143003800Z'/><EventRecordID>148521</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -96,6 +96,8 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4771</EventID><Version>0</Version><Level>0</Level><Task>14339</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-09-08T17:44:20.554179400Z'/><EventRecordID>391511</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -87,6 +87,8 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4776</EventID><Version>0</Version><Level>0</Level><Task>14336</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-09-08T19:03:50.057600300Z'/><EventRecordID>391615</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -104,6 +104,8 @@ fields:
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4781</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-04-09T22:22:45.521723900Z'/><EventRecordID>148763</EventRecordID><Correlation
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -95,6 +95,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4794</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-08-23T04:24:05.064689300Z'/><EventRecordID>821077</EventRecordID><Correlation
|
||||
|
||||
@@ -93,6 +93,8 @@ fields:
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4798</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-02-02T00:12:21.404799400Z'/><EventRecordID>386860</EventRecordID><Correlation
|
||||
|
||||
@@ -88,6 +88,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4876</EventID><Version>0</Version><Level>0</Level><Task>12805</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-02-06T16:27:05.403719800Z'/><EventRecordID>15379961</EventRecordID><Correlation
|
||||
|
||||
@@ -80,6 +80,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4886</EventID><Version>0</Version><Level>0</Level><Task>12805</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-02-06T13:13:36.529622400Z'/><EventRecordID>15379925</EventRecordID><Correlation
|
||||
|
||||
@@ -83,6 +83,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4887</EventID><Version>0</Version><Level>0</Level><Task>12805</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-06-09T14:54:02.171703300Z'/><EventRecordID>1830974609</EventRecordID><Correlation
|
||||
|
||||
@@ -98,6 +98,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>5136</EventID><Version>0</Version><Level>0</Level><Task>14081</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-11-17T20:51:01.321860300Z'/><EventRecordID>1997365</EventRecordID><Correlation
|
||||
|
||||
@@ -93,6 +93,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>5137</EventID><Version>0</Version><Level>0</Level><Task>14081</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2023-03-27T20:59:21.097880600Z'/><EventRecordID>170140</EventRecordID><Correlation/><Execution
|
||||
|
||||
@@ -99,6 +99,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
field_mappings:
|
||||
- data_model: ocsf
|
||||
mapping:
|
||||
|
||||
@@ -94,6 +94,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>5141</EventID><Version>0</Version><Le>0</Level><Task>14081</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
|
||||
SystemTime='2022-10-17T21:08:49.470503100Z'/><EventRecordID>670908</EventRecordID><Correlation
|
||||
|
||||
@@ -103,6 +103,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
field_mappings:
|
||||
- data_model: custom_cim
|
||||
data_set: Endpoint.Processes
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -114,4 +114,6 @@ fields:
|
||||
- user_group_id
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: 10/09/2020 10:41:26 AM
|
||||
|
||||
@@ -104,4 +104,6 @@ fields:
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: 10/09/2020 10:41:29 AM
|
||||
|
||||
@@ -104,3 +104,5 @@ fields:
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
@@ -75,6 +75,8 @@ fields:
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service
|
||||
Control Manager'/><EventID Qualifiers='16384'>7036</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated
|
||||
|
||||
@@ -79,6 +79,8 @@ fields:
|
||||
- user_id
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service
|
||||
Control Manager'/><EventID Qualifiers='16384'>7040</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated
|
||||
|
||||
@@ -79,6 +79,8 @@ fields:
|
||||
- user_id
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service
|
||||
Control Manager'/><EventID Qualifiers='16384'>7045</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated
|
||||
|
||||
@@ -77,6 +77,8 @@ fields:
|
||||
- user_id
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
|
||||
Name='Microsoft-Windows-TaskScheduler' Guid='{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}'/><EventID>200</EventID><Version>1</Version><Level>4</Level><Task>200</Task><Opcode>1</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
|
||||
SystemTime='2024-03-04T03:52:18.856458200Z'/><EventRecordID>4323</EventRecordID><Correlation
|
||||
|
||||
@@ -13,4 +13,6 @@ supported_TA:
|
||||
version: 9.0.1
|
||||
fields:
|
||||
- _time
|
||||
output_fields:
|
||||
- dest
|
||||
example_log: |-
|
||||
|
||||
@@ -0,0 +1,73 @@
|
||||
name: Zeek Conn
|
||||
id: 01dff429-9c29-4181-87ae-ea19cde20031
|
||||
version: 1
|
||||
date: '2025-03-12'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Zeek connection logs
|
||||
source: bro:conn:json
|
||||
sourcetype: bro:conn:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
fields:
|
||||
- action
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- conn_state
|
||||
- conn_state_meaning
|
||||
- dest
|
||||
- dest_host
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- duration
|
||||
- dvc
|
||||
- flow_id
|
||||
- history
|
||||
- id.orig_h
|
||||
- id.orig_p
|
||||
- id.resp_h
|
||||
- id.resp_p
|
||||
- id_orig_h
|
||||
- id_orig_p
|
||||
- id_resp_h
|
||||
- id_resp_p
|
||||
- is_broadcast
|
||||
- is_dest_internal_ip
|
||||
- is_src_internal_ip
|
||||
- local_orig
|
||||
- local_resp
|
||||
- missed_bytes
|
||||
- orig_bytes
|
||||
- orig_ip_bytes
|
||||
- orig_pkts
|
||||
- packets
|
||||
- packets_in
|
||||
- packets_out
|
||||
- product:
|
||||
- proto
|
||||
- resp_bytes
|
||||
- resp_ip_bytes
|
||||
- resp_pkts
|
||||
- sensor_name
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- tcp_flag
|
||||
- transport
|
||||
- ts
|
||||
- tunnel_parents
|
||||
- uid
|
||||
- vendor
|
||||
- vendor_product
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- dvc
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- vendor_product
|
||||
+7
-5
@@ -1,6 +1,6 @@
|
||||
name: Detect HTML Help Spawn Child Process
|
||||
id: 723716de-ee55-4cd4-9759-c44e7e55ba4b
|
||||
version: 9
|
||||
version: 10
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
@@ -19,8 +19,11 @@ data_source:
|
||||
- CrowdStrike ProcessRollup2
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=hh.exe
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process
|
||||
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
by Processes.action Processes.dest Processes.original_file_name Processes.parent_process
|
||||
Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id
|
||||
Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec
|
||||
Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level
|
||||
Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `detect_html_help_spawn_child_process_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Endpoint Detection
|
||||
@@ -87,7 +90,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: XmlWinEventLog
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Password Spray Attempts
|
||||
id: 086ab581-8877-42b3-9aee-4a7ecb0923af
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
@@ -13,40 +13,34 @@ description: This analytic employs the 3-sigma approach to detect an unusual vol
|
||||
many different accounts to avoid detection and account lockouts. By utilizing the
|
||||
Authentication Data Model, this detection is effective for all CIM-mapped authentication
|
||||
events, providing comprehensive coverage and enhancing security against these attacks.
|
||||
search: >-
|
||||
| tstats `security_content_summariesonly` values(Authentication.user) AS unique_user_names
|
||||
dc(Authentication.user) AS unique_accounts values(Authentication.app) as app count(Authentication.user)
|
||||
as total_failures from datamodel=Authentication.Authentication where Authentication.action="failure"
|
||||
NOT Authentication.src IN ("-","unknown") by Authentication.src, Authentication.action,
|
||||
Authentication.signature_id, sourcetype, _time span=5m | `drop_dm_object_name("Authentication")`
|
||||
```fill out time buckets for 0-count events during entire search length```
|
||||
| appendpipe [| timechart limit=0 span=5m count | table _time]
|
||||
| fillnull value=0 unique_accounts
|
||||
``` Create aggregation field & apply to all null events```
|
||||
| eval counter=src+"__"+sourcetype+"__"+signature_id | eventstats values(counter)
|
||||
as fnscounter | eval counter=coalesce(counter,fnscounter)
|
||||
``` stats version of mvexpand ```
|
||||
| stats values(app) as app values(unique_user_names) as unique_user_names values(total_failures)
|
||||
as total_failures values(src) as src values(signature_id) as signature_id values(sourcetype)
|
||||
as sourcetype count by counter unique_accounts _time
|
||||
``` remove duplicate time buckets for each unique source```
|
||||
| sort - _time unique_accounts
|
||||
| dedup _time counter
|
||||
```Find the outliers```
|
||||
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std
|
||||
by counter
|
||||
| eval upperBound=(comp_avg+comp_std*3)
|
||||
| eval isOutlier=if(unique_accounts > 30 and unique_accounts >= upperBound, 1, 0)
|
||||
| replace "::ffff:*" with * in src | where isOutlier=1 | foreach *
|
||||
[ eval <<FIELD>> = if(<<FIELD>>="null",null(),<<FIELD>>)]
|
||||
| table _time, src, action, app, unique_accounts, unique_user_names, total_failures,
|
||||
sourcetype, signature_id, counter
|
||||
| `detect_password_spray_attempts_filter`
|
||||
how_to_implement: >-
|
||||
Ensure in-scope authentication data is CIM mapped and the src field is populated
|
||||
with the source device. Also ensure fill_nullvalue is set within the macro security_content_summariesonly.
|
||||
This search opporates best on a 5 minute schedule, looking back over the past 70
|
||||
minutes. Configure 70 minute throttling on the two fields _time and counter.
|
||||
search: "| tstats `security_content_summariesonly` values(Authentication.user) AS\
|
||||
\ unique_user_names dc(Authentication.user) AS unique_accounts values(Authentication.app)\
|
||||
\ as app count(Authentication.user) as total_failures from datamodel=Authentication.Authentication\
|
||||
\ where Authentication.action=\"failure\" NOT Authentication.src IN (\"-\",\"unknown\"\
|
||||
) by Authentication.action Authentication.app Authentication.authentication_method\
|
||||
\ Authentication.dest \n Authentication.signature Authentication.signature_id Authentication.src\
|
||||
\ sourcetype _time span=5m \n| `drop_dm_object_name(\"Authentication\")`\n ```fill\
|
||||
\ out time buckets for 0-count events during entire search length```\n| appendpipe\
|
||||
\ [| timechart limit=0 span=5m count | table _time] | fillnull value=0 unique_accounts\n\
|
||||
\ ``` Create aggregation field & apply to all null events```\n| eval counter=src+\"\
|
||||
__\"+sourcetype+\"__\"+signature_id | eventstats values(counter) as fnscounter\
|
||||
\ | eval counter=coalesce(counter,fnscounter) \n ``` stats version of mvexpand\
|
||||
\ ```\n| stats values(app) as app values(unique_user_names) as unique_user_names\
|
||||
\ values(total_failures) as total_failures values(src) as src values(signature_id)\
|
||||
\ as signature_id values(sourcetype) as sourcetype count by counter unique_accounts\
|
||||
\ _time\n ``` remove duplicate time buckets for each unique source```\n| sort\
|
||||
\ - _time unique_accounts | dedup _time counter\n ```Find the outliers```\n|\
|
||||
\ eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std\
|
||||
\ by counter | eval upperBound=(comp_avg+comp_std*3) | eval isOutlier=if(unique_accounts\
|
||||
\ > 30 and unique_accounts >= upperBound, 1, 0) | replace \"::ffff:*\" with * in\
|
||||
\ src | where isOutlier=1 | foreach * \n [ eval <<FIELD>> = if(<<FIELD>>=\"\
|
||||
null\",null(),<<FIELD>>)] \n| table _time, src, action, app, unique_accounts, unique_user_names,\
|
||||
\ total_failures, sourcetype, signature_id, counter | `detect_password_spray_attempts_filter`"
|
||||
how_to_implement: 'Ensure in-scope authentication data is CIM mapped and the src field
|
||||
is populated with the source device. Also ensure fill_nullvalue is set within the
|
||||
macro security_content_summariesonly. This search opporates best on a 5 minute schedule,
|
||||
looking back over the past 70 minutes. Configure 70 minute throttling on the two
|
||||
fields _time and counter. '
|
||||
known_false_positives: Unknown
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1110/003/
|
||||
@@ -91,7 +85,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Email files written outside of the Outlook directory
|
||||
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
@@ -19,9 +19,11 @@ search: '| tstats `security_content_summariesonly` count values(Filesystem.file_
|
||||
as file_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem
|
||||
where (Filesystem.file_name=*.pst OR Filesystem.file_name=*.ost) Filesystem.file_path
|
||||
!= "C:\\Users\\*\\My Documents\\Outlook Files\\*" Filesystem.file_path!="C:\\Users\\*\\AppData\\Local\\Microsoft\\Outlook*"
|
||||
by Filesystem.action Filesystem.process_id Filesystem.file_name Filesystem.dest
|
||||
| `drop_dm_object_name("Filesystem")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
|
||||
`email_files_written_outside_of_the_outlook_directory_filter`'
|
||||
by Filesystem.action Filesystem.dest Filesystem.file_access_time Filesystem.file_create_time
|
||||
Filesystem.file_hash Filesystem.file_modify_time Filesystem.file_name Filesystem.file_path
|
||||
Filesystem.file_acl Filesystem.file_size Filesystem.process_guid Filesystem.process_id
|
||||
Filesystem.user Filesystem.vendor_product | `drop_dm_object_name("Filesystem")`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `email_files_written_outside_of_the_outlook_directory_filter`'
|
||||
how_to_implement: To successfully implement this search, you must be ingesting data
|
||||
that records the file-system activity from your hosts to populate the Endpoint.Filesystem
|
||||
data model node. This is typically populated via endpoint detection-and-response
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Okta Multi-Factor Authentication Disabled
|
||||
id: 7c0348ce-bdf9-45f6-8a57-c18b5976f00a
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
@@ -19,8 +19,8 @@ search: '| tstats `security_content_summariesonly` count max(_time) as lastTime,
|
||||
as firstTime from datamodel=Change where sourcetype="OktaIM2:log" All_Changes.object_category=User
|
||||
AND All_Changes.action=modified All_Changes.command=user.mfa.factor.deactivate by
|
||||
All_Changes.user All_Changes.result All_Changes.command sourcetype All_Changes.src
|
||||
| `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `okta_multi_factor_authentication_disabled_filter`'
|
||||
All_Changes.dest | `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `okta_multi_factor_authentication_disabled_filter`'
|
||||
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
|
||||
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
|
||||
known_false_positives: Legitimate use case may require for users to disable MFA. Filter
|
||||
@@ -66,7 +66,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/okta_mfa_method_disabled/okta_mfa_method_disabled.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/okta_mfa_method_disabled/okta_mfa_method_disabled.log
|
||||
source: Okta
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Okta Multiple Accounts Locked Out
|
||||
id: a511426e-184f-4de6-8711-cfd2af29d1e1
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2025-01-21'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
@@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count max(_time) as lastTime,
|
||||
as firstTime values(All_Changes.user) as user from datamodel=Change where All_Changes.change_type=AAA
|
||||
All_Changes.object_category=User AND All_Changes.action=lockout AND All_Changes.command=user.account.lock
|
||||
by _time span=5m All_Changes.result All_Changes.command sourcetype All_Changes.src
|
||||
| where count > 5 | `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)`
|
||||
All_Changes.dest | where count > 5 | `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `okta_multiple_accounts_locked_out_filter`'
|
||||
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
|
||||
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
|
||||
@@ -65,7 +65,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/okta_multiple_accounts_lockout/okta_multiple_accounts_lockout.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/okta_multiple_accounts_lockout/okta_multiple_accounts_lockout.log
|
||||
source: Okta
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Okta Multiple Failed MFA Requests For User
|
||||
id: 826dbaae-a1e6-4c8c-b384-d16898956e73
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-01-21'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
@@ -17,8 +17,8 @@ description: The following analytic identifies multiple failed multi-factor auth
|
||||
search: '`okta` eventType=user.authentication.auth_via_mfa outcome.result=FAILURE
|
||||
debugContext.debugData.factor!=PASSWORD_AS_FACTOR | bucket _time span=5m | stats
|
||||
count min(_time) as firstTime max(_time) as lastTime values(displayMessage) values(src_ip)
|
||||
as src_ip values(debugContext.debugData.factor) by _time src_user | where count
|
||||
>= 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
as src_ip values(debugContext.debugData.factor) values(dest) as dest by _time src_user
|
||||
| where count >= 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `okta_multiple_failed_mfa_requests_for_user_filter`'
|
||||
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
|
||||
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
|
||||
@@ -63,7 +63,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/okta_multiple_failed_mfa_requests/okta_multiple_failed_mfa_requests.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/okta_multiple_failed_mfa_requests/okta_multiple_failed_mfa_requests.log
|
||||
source: Okta
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Okta Multiple Users Failing To Authenticate From Ip
|
||||
id: de365ffa-42f5-46b5-b43f-fa72290b8218
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-01-21'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
@@ -18,9 +18,10 @@ description: The following analytic identifies instances where more than 10 uniq
|
||||
search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time)
|
||||
as firstTime dc(Authentication.user) as unique_accounts values(Authentication.signature)
|
||||
as signature values(Authentication.user) as user values(Authentication.app) as app
|
||||
values(Authentication.authentication_method) as authentication_method from datamodel=Authentication
|
||||
where Authentication.action="failure" AND Authentication.signature=user.session.start
|
||||
by _time span=5m Authentication.src sourcetype | where unique_accounts > 9 | `drop_dm_object_name("Authentication")`
|
||||
values(Authentication.authentication_method) as authentication_method values(Authentication.dest)
|
||||
as dest from datamodel=Authentication where Authentication.action="failure" AND
|
||||
Authentication.signature=user.session.start by _time span=5m Authentication.src
|
||||
sourcetype | where unique_accounts > 9 | `drop_dm_object_name("Authentication")`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_multiple_users_failing_to_authenticate_from_ip_filter`'
|
||||
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
|
||||
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
|
||||
@@ -67,7 +68,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/okta_multiple_users_from_ip/okta_multiple_users_from_ip.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/okta_multiple_users_from_ip/okta_multiple_users_from_ip.log
|
||||
source: Okta
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Okta New API Token Created
|
||||
id: c3d22720-35d3-4da4-bd0a-740d37192bd4
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -18,8 +18,9 @@ data_source:
|
||||
search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time)
|
||||
as firstTime from datamodel=Change where All_Changes.action=created AND All_Changes.command=system.api_token.create
|
||||
by _time span=5m All_Changes.user All_Changes.result All_Changes.command sourcetype
|
||||
All_Changes.src All_Changes.action All_Changes.object_category | `drop_dm_object_name("All_Changes")`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_new_api_token_created_filter`'
|
||||
All_Changes.src All_Changes.action All_Changes.object_category All_Changes.dest
|
||||
| `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `okta_new_api_token_created_filter`'
|
||||
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
|
||||
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
|
||||
known_false_positives: False positives may be present. Tune Okta and tune the analytic
|
||||
@@ -63,7 +64,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.001/okta_new_api_token_created/okta_new_api_token_created.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.001/okta_new_api_token_created/okta_new_api_token_created.log
|
||||
source: Okta
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Okta New Device Enrolled on Account
|
||||
id: bb27cbce-d4de-432c-932f-2e206e9130fb
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -18,8 +18,9 @@ data_source:
|
||||
search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time)
|
||||
as firstTime from datamodel=Change where All_Changes.action=created All_Changes.command=device.enrollment.create
|
||||
by _time span=5m All_Changes.user All_Changes.result All_Changes.command sourcetype
|
||||
All_Changes.src All_Changes.action All_Changes.object_category | `drop_dm_object_name("All_Changes")`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_new_device_enrolled_on_account_filter`'
|
||||
All_Changes.src All_Changes.action All_Changes.object_category All_Changes.dest
|
||||
| `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `okta_new_device_enrolled_on_account_filter`'
|
||||
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
|
||||
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
|
||||
known_false_positives: It is possible that the user has legitimately added a new device
|
||||
@@ -63,7 +64,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.005/okta_new_device_enrolled/okta_new_device_enrolled.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.005/okta_new_device_enrolled/okta_new_device_enrolled.log
|
||||
source: Okta
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Okta Successful Single Factor Authentication
|
||||
id: 98f6ad4f-4325-4096-9d69-45dc8e638e82
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
data_source:
|
||||
@@ -18,7 +18,7 @@ search: '`okta` action=success src_user_type = User eventType = user.authentica
|
||||
OR eventType = user.authentication.auth_via_mfa| stats dc(eventType) values(eventType)
|
||||
as eventType values(target{}.displayName) as targets values(debugContext.debugData.url)
|
||||
min(_time) as firstTime max(_time) as lastTime values(authentication_method) by
|
||||
src_ip user action | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
src_ip user action dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| search targets !="Okta Verify" | `okta_successful_single_factor_authentication_filter`'
|
||||
how_to_implement: This detection utilizes logs from Okta environments and requires
|
||||
the ingestion of OktaIm2 logs through the Splunk Add-on for Okta Identity Cloud
|
||||
@@ -66,7 +66,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/okta_single_factor_auth/okta_single_factor_auth.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/okta_single_factor_auth/okta_single_factor_auth.log
|
||||
source: okta_log
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Okta Suspicious Activity Reported
|
||||
id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
@@ -17,7 +17,7 @@ data_source:
|
||||
- Okta
|
||||
search: '`okta` eventType=user.account.report_suspicious_activity_by_enduser | stats
|
||||
count min(_time) as firstTime max(_time) as lastTime values(displayMessage) by user
|
||||
eventType client.userAgent.rawUserAgent client.userAgent.browser client.geographicalContext.city client.geographicalContext.country
|
||||
dest src eventType client.userAgent.rawUserAgent client.userAgent.browser client.geographicalContext.city client.geographicalContext.country
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_suspicious_activity_reported_filter`'
|
||||
how_to_implement: This detection utilizes logs from Okta Identity Management (IM)
|
||||
environments. It requires the ingestion of OktaIm2 logs through the Splunk Add-on
|
||||
@@ -64,7 +64,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/okta_suspicious_activity_reported_by_user/okta_suspicious_activity_reported_by_user.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/okta_suspicious_activity_reported_by_user/okta_suspicious_activity_reported_by_user.log
|
||||
source: Okta
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user