Merge branch 'develop' into jp_paranoid

This commit is contained in:
Bhavin Patel
2025-04-02 12:07:51 -07:00
committed by GitHub
1181 changed files with 12160 additions and 8546 deletions
+1 -1
View File
@@ -45,7 +45,7 @@ jobs:
git fetch origin pull/${{ github.event.pull_request.number }}/head:new_branch_for_testing
#We must specifically get the PR's target branch from security_content, not the one that resides in the fork PR's forked repo
git switch new_branch_for_testing
contentctl test --disable-tqdm --no-enable-integration-testing --container-settings.num-containers 2 --post-test-behavior never_pause mode:changes --mode.target-branch ${{ github.base_ref }}
contentctl test --verbose --disable-tqdm --no-enable-integration-testing --container-settings.num-containers 2 --post-test-behavior never_pause mode:changes --mode.target-branch ${{ github.base_ref }}
echo "contentctl test - COMPLETED"
continue-on-error: true
@@ -69,5 +69,14 @@ fields:
- vendor_product
- version
- vpcflow_action
output_fields:
- action
- src
- src_ip
- src_port
- dest
- dest_ip
- dest_port
- transport
example_log: 2 123397614277 eni-0b0f9f261f45e6489 10.0.1.30 10.0.1.1 47254 22 17 2
98 1697608042 1697608070 ACCEPT OK
@@ -99,6 +99,27 @@ fields:
- user
- user_id
- vendor_product
output_fields:
- action
- dest
- original_file_name
- parent_process
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_exec
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- user
- user_id
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
+4
View File
@@ -17,3 +17,7 @@ supported_TA:
- name: Splunk Add-on for Okta Identity Cloud
url: https://splunkbase.splunk.com/app/6553
version: 3.0.0
output_fields:
- dest
- src
- user
@@ -27,6 +27,13 @@ field_mappings:
url: Web.url
url_length: Web.url_length
src: Web.src
output_fields:
- http_user_agent
- http_method
- url
- url_length
- src
- dest
fields:
- _time
- date_hour
@@ -36,6 +36,24 @@ fields:
- splunk_server
- timeendpos
- timestartpos
output_fields:
- action
- app
- bytes
- bytes_in
- bytes_out
- dest
- dest_ip
- dest_port
- dvc
- protocol
- protocol_version
- src
- src_ip
- src_port
- transport
- user
- vendor_product
field_mappings:
- data_model: cim
data_set: All_Traffic
@@ -73,6 +73,19 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- signature
- signature_id
- user_id
- vendor_product
- Guid
- Opcode
- Name
- Path
- ProcessID
- ScriptBlockId
- ScriptBlockText
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
+21
View File
@@ -117,6 +117,27 @@ fields:
- user
- user_id
- vendor_product
output_fields:
- action
- dest
- original_file_name
- parent_process
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_exec
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- user
- user_id
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
+13
View File
@@ -98,6 +98,19 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- user_id
- parent_process_name
- parent_process_guid
- process_name
- process_guid
- process_id
- signature
- SourceImage
- TargetImage
- GrantedAccess
- CallTrace
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>10</EventID><Version>3</Version><Level>4</Level><Task>10</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2022-02-01T21:01:44.672666100Z'/><EventRecordID>150624412</EventRecordID><Correlation/><Execution
+9
View File
@@ -92,6 +92,15 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- action
- dest
- file_name
- file_path
- process_guid
- process_id
- user
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Filesystem
+11
View File
@@ -94,6 +94,17 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- action
- dest
- process_guid
- process_id
- registry_hive
- registry_path
- registry_key_name
- status
- user
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Registry
+13
View File
@@ -101,6 +101,19 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- action
- dest
- process_guid
- process_id
- registry_hive
- registry_path
- registry_key_name
- registry_value_data
- registry_value_name
- status
- user
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Registry
+15
View File
@@ -97,6 +97,21 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- dvc
- file_hash
- file_name
- file_path
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>15</EventID><Version>2</Version><Level>4</Level><Task>15</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2021-04-28T20:11:34.709744300Z'/><EventRecordID>667860</EventRecordID><Correlation/><Execution
+13
View File
@@ -85,6 +85,19 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- dvc
- pipe_name
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>17</EventID><Version>1</Version><Level>4</Level><Task>17</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2021-04-19T21:00:18.288457000Z'/><EventRecordID>162168</EventRecordID><Correlation/><Execution
+13
View File
@@ -89,6 +89,19 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- dvc
- pipe_name
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>18</EventID><Version>1</Version><Level>4</Level><Task>18</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2021-04-19T21:00:19.312721800Z'/><EventRecordID>162173</EventRecordID><Correlation/><Execution
+13
View File
@@ -91,6 +91,19 @@ fields:
- user_id
- user_name
- vendor_product
output_fields:
- dest
- dvc
- object
- object_category
- object_path
- signature
- signature_id
- src
- status
- user
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>20</EventID><Version>3</Version><Level>4</Level><Task>20</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2020-12-08T13:54:48.517698800Z'/><EventRecordID>6249</EventRecordID><Correlation/><Execution
+14
View File
@@ -94,6 +94,20 @@ fields:
- user_id
- user_name
- vendor_product
output_fields:
- dest
- dvc
- object
- object_attrs
- object_category
- object_path
- signature
- signature_id
- src
- status
- user
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>21</EventID><Version>3</Version><Level>4</Level><Task>21</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2021-06-16T21:46:50.225290200Z'/><EventRecordID>151644</EventRecordID><Correlation/><Execution
+8
View File
@@ -95,6 +95,14 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- answer
- answer_count
- query
- query_count
- reply_code_id
- src
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>22</EventID><Version>5</Version><Level>4</Level><Task>22</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2021-03-24T12:25:15.098978900Z'/><EventRecordID>113892</EventRecordID><Correlation/><Execution
+18
View File
@@ -100,6 +100,24 @@ fields:
- user
- user_id
- vendor_product
output_fields:
- action
- dest
- dvc
- file_path
- file_hash
- file_name
- file_modify_time
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>23</EventID><Version>5</Version><Level>4</Level><Task>23</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2023-02-01T10:57:09.815326000Z'/><EventRecordID>281771</EventRecordID><Correlation/><Execution
+18
View File
@@ -14,4 +14,22 @@ supported_TA:
version: 4.0.2
fields:
- _time
output_fields:
- action
- dest
- dvc
- file_path
- file_hash
- file_name
- file_modify_time
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user
- user_id
- vendor_product
example_log: |-
+16
View File
@@ -114,6 +114,22 @@ fields:
- user
- user_id
- vendor_product
output_fields:
- action
- app
- dest
- dest_ip
- dest_port
- direction
- dvc
- protocol
- protocol_version
- src
- src_ip
- src_port
- transport
- user
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>3</EventID><Version>5</Version><Level>4</Level><Task>3</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2022-09-15T12:56:22.958249300Z'/><EventRecordID>156837</EventRecordID><Correlation/><Execution
+12
View File
@@ -86,6 +86,18 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- process
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>5</EventID><Version>3</Version><Level>4</Level><Task>5</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2021-03-16T14:01:44.008858500Z'/><EventRecordID>39965</EventRecordID><Correlation/><Execution
+9
View File
@@ -88,6 +88,15 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- dvc
- process_hash
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>6</EventID><Version>4</Version><Level>4</Level><Task>6</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2022-04-04T17:37:04.643206900Z'/><EventRecordID>15708989</EventRecordID><Correlation/><Execution
+18
View File
@@ -108,6 +108,24 @@ fields:
- user
- user_id
- vendor_product
output_fields:
- Image
- ImageLoaded
- dest
- loaded_file
- loaded_file_path
- process_exec
- process_guid
- process_hash
- process_id
- process_name
- process_path
- service_dll_signature_exists
- service_dll_signature_verified
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>7</EventID><Version>3</Version><Level>4</Level><Task>7</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2023-09-12T08:06:31.445185300Z'/><EventRecordID>45273</EventRecordID><Correlation/><Execution
+16
View File
@@ -100,6 +100,22 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>8</EventID><Version>2</Version><Level>4</Level><Task>8</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2022-10-27T13:59:12.440938600Z'/><EventRecordID>362233</EventRecordID><Correlation/><Execution
+12
View File
@@ -87,6 +87,18 @@ fields:
- timestartpos
- user_id
- vendor_product
output_fields:
- dest
- dvc
- process_exec
- process_guid
- process_id
- process_name
- process_path
- signature
- signature_id
- user_id
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Sysmon' Guid='{5770385F-C22A-43E0-BF4C-06F5698FFBD9}'/><EventID>9</EventID><Version>2</Version><Level>4</Level><Task>9</Task><Opcode>0</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2022-02-25T12:25:33.375618100Z'/><EventRecordID>190607</EventRecordID><Correlation/><Execution
@@ -108,6 +108,27 @@ fields:
- timestartpos
- user
- vendor_product
output_fields:
- action
- dest
- original_file_name
- parent_process
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_exec
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- user
- user_id
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
@@ -85,6 +85,21 @@ fields:
- timestartpos
- user
- vendor_product
output_fields:
- action
- dest
- file_access_time
- file_create_time
- file_hash
- file_modify_time
- file_name
- file_path
- file_acl
- file_size
- process_guid
- process_id
- user
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Filesystem
@@ -68,6 +68,8 @@ fields:
- timeendpos
- timestartpos
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-IIS-W3SVC-WP' Guid='{670080D9-742A-4187-8D16-41143D1290BD}'
EventSourceName='W3SVC-WP'/><EventID Qualifiers='49152'>2282</EventID><Version>0</Version><Level>2</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated
@@ -63,6 +63,8 @@ fields:
- timestamp
- user_id
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-ProcessExitMonitor' Guid='{FD771D53-8492-4057-8E35-8C02813AF49B}'
EventSourceName='Process Exit Monitor'/><EventID Qualifiers='16384'>3000</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated
@@ -77,6 +77,22 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- action
- app
- change_type
- dest
- dvc
- name
- object_attrs
- object_category
- service
- service_name
- signature
- signature_id
- status
- subject
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Eventlog' Guid='{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'/><EventID>1100</EventID><Version>0</Version><Level>4</Level><Task>103</Task><Opcode>0</Opcode><Keywords>0x4020000000000000</Keywords><TimeCreated
SystemTime='2024-04-08T18:48:10.378485000Z'/><EventRecordID>140874</EventRecordID><Correlation/><Execution
@@ -83,6 +83,22 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- action
- app
- change_type
- dest
- dvc
- name
- object_attrs
- object_category
- signature
- signature_id
- src_user
- status
- subject
- user
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Eventlog' Guid='{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'/><EventID>1102</EventID><Version>0</Version><Level>4</Level><Task>104</Task><Opcode>0</Opcode><Keywords>0x4020000000000000</Keywords><TimeCreated
SystemTime='2024-03-05T09:18:29.313328400Z'/><EventRecordID>1826166</EventRecordID><Correlation/><Execution
@@ -121,6 +121,15 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- action
- app
- authentication_method
- dest
- signature
- signature_id
- src
- user
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4624</EventID><Version>2</Version><Level>0</Level><Task>12544</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2023-03-23T19:15:28.337312500Z'/><EventRecordID>371886</EventRecordID><Correlation
@@ -116,6 +116,15 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- action
- app
- authentication_method
- dest
- signature
- signature_id
- src
- user
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4625</EventID><Version>0</Version><Level>0</Level><Task>12544</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
SystemTime='2023-03-22T20:25:15.594676400Z'/><EventRecordID>367348</EventRecordID><Correlation
@@ -96,6 +96,13 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- action
- app
- dest
- signature_id
- user
- vendor_product
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4627</EventID><Version>0</Version><Level>0</Level><Task>12554</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2023-10-05T20:02:43.026235200Z'/><EventRecordID>186260</EventRecordID><Correlation
@@ -109,6 +109,10 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- dest
- src_ip
- user
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4648</EventID><Version>0</Version><Level>0</Level><Task>12544</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2022-09-08T21:33:47.813673700Z'/><EventRecordID>336567</EventRecordID><Correlation
@@ -96,6 +96,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4662</EventID><Version>0</Version><Level>0</Level><Task>14080</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
SystemTime='2023-02-02T22:41:45.751175400Z'/><EventRecordID>21623198276</EventRecordID><Correlation
@@ -101,6 +101,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4663</EventID><Version>1</Version><Level>0</Level><Task>12800</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-02-21T14:08:33.452364300Z'/><EventRecordID>10525869</EventRecordID><Correlation/><Execution
@@ -86,6 +86,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4672</EventID><Version>0</Version><Level>0</Level><Task>12548</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2023-03-27T18:35:15.439521100Z'/><EventRecordID>148946</EventRecordID><Correlation
@@ -94,6 +94,27 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- action
- dest
- original_file_name
- parent_process
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_exec
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- user
- user_id
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
@@ -88,4 +88,6 @@ fields:
- user
- vendor
- vendor_product
output_fields:
- dest
example_log: 04/26/2022 11:12:09 AM
@@ -87,4 +87,6 @@ fields:
- user
- vendor
- vendor_product
output_fields:
- dest
example_log: 11/12/2021 05:16:44 PM
@@ -104,6 +104,8 @@ fields:
- user_name
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4703</EventID><Version>0</Version><Level>0</Level><Task>13317</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2022-08-31T09:47:43.137598500Z'/><EventRecordID>328761</EventRecordID><Correlation/><Execution
@@ -91,6 +91,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4719</EventID><Version>0</Version><Level>0</Level><Task>13568</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2022-11-03T00:02:53.722907800Z'/><EventRecordID>353597</EventRecordID><Correlation
@@ -110,4 +110,6 @@ fields:
- user_group_id
- vendor
- vendor_product
output_fields:
- dest
example_log: 10/09/2020 10:41:26 AM
@@ -100,6 +100,8 @@ fields:
- user_name
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4724</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-02-21T18:02:22.774396900Z'/><EventRecordID>276779</EventRecordID><Correlation/><Execution
@@ -99,6 +99,8 @@ fields:
- user_name
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4725</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-02-21T19:20:19.727858200Z'/><EventRecordID>278771</EventRecordID><Correlation/><Execution
@@ -100,6 +100,8 @@ fields:
- user_name
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4726</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-02-21T19:38:47.481373400Z'/><EventRecordID>279283</EventRecordID><Correlation/><Execution
@@ -13,5 +13,7 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4727</EventID><Version>0</Version><Level>0</Level><Task>13826</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime='2024-07-30T16:51:45.175123800Z'/><EventRecordID>183204880</EventRecordID><Correlation/><Execution ProcessID='672' ThreadID='3064'/><Channel>Security</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security/></System><EventData><Data Name='TargetUserName'>ESX Admins</Data><Data Name='TargetDomainName'>ATTACKRANGE</Data><Data Name='TargetSid'>ATTACKRANGE\ESX Admins</Data><Data Name='SubjectUserSid'>ATTACKRANGE\Administrator</Data><Data Name='SubjectUserName'>administrator</Data><Data Name='SubjectDomainName'>ATTACKRANGE</Data><Data Name='SubjectLogonId'>0xe32f0</Data><Data Name='PrivilegeList'>-</Data><Data Name='SamAccountName'>ESX Admins</Data><Data Name='SidHistory'>-</Data></EventData></Event>
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -99,5 +99,7 @@ fields:
- _sourcetype
- _subsecond
- _time
output_fields:
- dest
example_log: |-
<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4730</EventID><Version>0</Version><Level>0</Level><Task>13826</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime='2024-07-30T16:51:39.613057200Z'/><EventRecordID>183203591</EventRecordID><Correlation/><Execution ProcessID='672' ThreadID='2420'/><Channel>Security</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security/></System><EventData><Data Name='TargetUserName'>ESX Admins</Data><Data Name='TargetDomainName'>ATTACKRANGE</Data><Data Name='TargetSid'>S-1-5-21-560616516-1175754387-3922768235-4211</Data><Data Name='SubjectUserSid'>ATTACKRANGE\Administrator</Data><Data Name='SubjectUserName'>administrator</Data><Data Name='SubjectDomainName'>ATTACKRANGE</Data><Data Name='SubjectLogonId'>0xe32f0</Data><Data Name='PrivilegeList'>-</Data></EventData></Event>
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -99,4 +99,6 @@ fields:
- vendor
- vendor_privilege
- vendor_product
output_fields:
- dest
example_log: 10/09/2020 10:41:26 AM
@@ -99,6 +99,8 @@ fields:
- _sourcetype
- _subsecond
- _time
output_fields:
- dest
example_log: |-
<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4737</EventID><Version>0</Version><Level>0</Level><Task>13826</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime='2024-07-30T16:50:34.812948700Z'/><EventRecordID>183186860</EventRecordID><Correlation/><Execution ProcessID='672' ThreadID='900'/><Channel>Security</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security/></System><EventData><Data Name='TargetUserName'>ESX Admins</Data><Data Name='TargetDomainName'>ATTACKRANGE</Data><Data Name='TargetSid'>S-1-5-21-560616516-1175754387-3922768235-4211</Data><Data Name='SubjectUserSid'>ATTACKRANGE\Administrator</Data><Data Name='SubjectUserName'>administrator</Data><Data Name='SubjectDomainName'>ATTACKRANGE</Data><Data Name='SubjectLogonId'>0xe32f0</Data><Data Name='PrivilegeList'>-</Data><Data Name='SamAccountName'>-</Data><Data Name='SidHistory'>-</Data></EventData></Event>
@@ -120,6 +120,8 @@ fields:
- user_name
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4738</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2022-11-17T03:25:57.674067800Z'/><EventRecordID>6389713</EventRecordID><Correlation/><Execution
@@ -108,6 +108,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4739</EventID><Version>0</Version><Level>0</Level><Task>13569</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-02-02T00:37:16.161168500Z'/><EventRecordID>394176</EventRecordID><Correlation/><Execution
@@ -121,6 +121,8 @@ fields:
- user_type
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4741</EventID><Version>0</Version><Level>0</Level><Task>13825</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-04-08T18:48:04.618400500Z'/><EventRecordID>143475</EventRecordID><Correlation/><Execution
@@ -121,6 +121,8 @@ fields:
- user_type
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4742</EventID><Version>0</Version><Level>0</Level><Task>13825</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2022-08-04T09:26:26.793335600Z'/><EventRecordID>901860</EventRecordID><Correlation/><Execution
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -102,6 +102,8 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4768</EventID><Version>0</Version><Level>0</Level><Task>14339</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
SystemTime='2022-09-08T18:16:25.601071000Z'/><EventRecordID>391562</EventRecordID><Correlation/><Execution
@@ -102,6 +102,8 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4769</EventID><Version>0</Version><Level>0</Level><Task>14337</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-04-09T01:00:49.143003800Z'/><EventRecordID>148521</EventRecordID><Correlation/><Execution
@@ -96,6 +96,8 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4771</EventID><Version>0</Version><Level>0</Level><Task>14339</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
SystemTime='2022-09-08T17:44:20.554179400Z'/><EventRecordID>391511</EventRecordID><Correlation/><Execution
@@ -87,6 +87,8 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4776</EventID><Version>0</Version><Level>0</Level><Task>14336</Task><Opcode>0</Opcode><Keywords>0x8010000000000000</Keywords><TimeCreated
SystemTime='2022-09-08T19:03:50.057600300Z'/><EventRecordID>391615</EventRecordID><Correlation/><Execution
@@ -104,6 +104,8 @@ fields:
- user_name
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>4781</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-04-09T22:22:45.521723900Z'/><EventRecordID>148763</EventRecordID><Correlation
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -95,6 +95,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4794</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2022-08-23T04:24:05.064689300Z'/><EventRecordID>821077</EventRecordID><Correlation
@@ -93,6 +93,8 @@ fields:
- user_group
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4798</EventID><Version>0</Version><Level>0</Level><Task>13824</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2024-02-02T00:12:21.404799400Z'/><EventRecordID>386860</EventRecordID><Correlation
@@ -88,6 +88,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4876</EventID><Version>0</Version><Level>0</Level><Task>12805</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2023-02-06T16:27:05.403719800Z'/><EventRecordID>15379961</EventRecordID><Correlation
@@ -80,6 +80,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4886</EventID><Version>0</Version><Level>0</Level><Task>12805</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2023-02-06T13:13:36.529622400Z'/><EventRecordID>15379925</EventRecordID><Correlation
@@ -83,6 +83,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>4887</EventID><Version>0</Version><Level>0</Level><Task>12805</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2023-06-09T14:54:02.171703300Z'/><EventRecordID>1830974609</EventRecordID><Correlation
@@ -98,6 +98,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>5136</EventID><Version>0</Version><Level>0</Level><Task>14081</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2022-11-17T20:51:01.321860300Z'/><EventRecordID>1997365</EventRecordID><Correlation
@@ -93,6 +93,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-a5ba-3e3b0328c30d}'/><EventID>5137</EventID><Version>0</Version><Level>0</Level><Task>14081</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2023-03-27T20:59:21.097880600Z'/><EventRecordID>170140</EventRecordID><Correlation/><Execution
@@ -99,6 +99,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
field_mappings:
- data_model: ocsf
mapping:
@@ -94,6 +94,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>5141</EventID><Version>0</Version><Le>0</Level><Task>14081</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated
SystemTime='2022-10-17T21:08:49.470503100Z'/><EventRecordID>670908</EventRecordID><Correlation
@@ -103,6 +103,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
field_mappings:
- data_model: custom_cim
data_set: Endpoint.Processes
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
@@ -114,4 +114,6 @@ fields:
- user_group_id
- vendor
- vendor_product
output_fields:
- dest
example_log: 10/09/2020 10:41:26 AM
@@ -104,4 +104,6 @@ fields:
- user_name
- vendor
- vendor_product
output_fields:
- dest
example_log: 10/09/2020 10:41:29 AM
@@ -104,3 +104,5 @@ fields:
- user_name
- vendor
- vendor_product
output_fields:
- dest
@@ -75,6 +75,8 @@ fields:
- timestartpos
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service
Control Manager'/><EventID Qualifiers='16384'>7036</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated
@@ -79,6 +79,8 @@ fields:
- user_id
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service
Control Manager'/><EventID Qualifiers='16384'>7040</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated
@@ -79,6 +79,8 @@ fields:
- user_id
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Service Control Manager' Guid='{555908d1-a6d7-4695-8e1e-26931d2012f4}' EventSourceName='Service
Control Manager'/><EventID Qualifiers='16384'>7045</EventID><Version>0</Version><Level>4</Level><Task>0</Task><Opcode>0</Opcode><Keywords>0x8080000000000000</Keywords><TimeCreated
@@ -77,6 +77,8 @@ fields:
- user_id
- vendor
- vendor_product
output_fields:
- dest
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider
Name='Microsoft-Windows-TaskScheduler' Guid='{DE7B24EA-73C8-4A09-985D-5BDADCFA9017}'/><EventID>200</EventID><Version>1</Version><Level>4</Level><Task>200</Task><Opcode>1</Opcode><Keywords>0x8000000000000000</Keywords><TimeCreated
SystemTime='2024-03-04T03:52:18.856458200Z'/><EventRecordID>4323</EventRecordID><Correlation
@@ -13,4 +13,6 @@ supported_TA:
version: 9.0.1
fields:
- _time
output_fields:
- dest
example_log: |-
+73
View File
@@ -0,0 +1,73 @@
name: Zeek Conn
id: 01dff429-9c29-4181-87ae-ea19cde20031
version: 1
date: '2025-03-12'
author: Patrick Bareiss, Splunk
description: Data source object for Zeek connection logs
source: bro:conn:json
sourcetype: bro:conn:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
fields:
- action
- bytes
- bytes_in
- bytes_out
- conn_state
- conn_state_meaning
- dest
- dest_host
- dest_ip
- dest_port
- duration
- dvc
- flow_id
- history
- id.orig_h
- id.orig_p
- id.resp_h
- id.resp_p
- id_orig_h
- id_orig_p
- id_resp_h
- id_resp_p
- is_broadcast
- is_dest_internal_ip
- is_src_internal_ip
- local_orig
- local_resp
- missed_bytes
- orig_bytes
- orig_ip_bytes
- orig_pkts
- packets
- packets_in
- packets_out
- product:
- proto
- resp_bytes
- resp_ip_bytes
- resp_pkts
- sensor_name
- src
- src_ip
- src_port
- tcp_flag
- transport
- ts
- tunnel_parents
- uid
- vendor
- vendor_product
output_fields:
- action
- dest
- dest_ip
- dest_port
- dvc
- src
- src_ip
- src_port
- vendor_product
@@ -1,6 +1,6 @@
name: Detect HTML Help Spawn Child Process
id: 723716de-ee55-4cd4-9759-c44e7e55ba4b
version: 9
version: 10
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
@@ -19,8 +19,11 @@ data_source:
- CrowdStrike ProcessRollup2
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=hh.exe
by Processes.dest Processes.user Processes.parent_process_name Processes.parent_process
Processes.process_name Processes.process Processes.process_id Processes.parent_process_id
by Processes.action Processes.dest Processes.original_file_name Processes.parent_process
Processes.parent_process_exec Processes.parent_process_guid Processes.parent_process_id
Processes.parent_process_name Processes.parent_process_path Processes.process Processes.process_exec
Processes.process_guid Processes.process_hash Processes.process_id Processes.process_integrity_level
Processes.process_name Processes.process_path Processes.user Processes.user_id Processes.vendor_product
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `detect_html_help_spawn_child_process_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
@@ -87,7 +90,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
@@ -1,6 +1,6 @@
name: Detect Password Spray Attempts
id: 086ab581-8877-42b3-9aee-4a7ecb0923af
version: 6
version: 7
date: '2025-02-10'
author: Dean Luxton
status: production
@@ -13,40 +13,34 @@ description: This analytic employs the 3-sigma approach to detect an unusual vol
many different accounts to avoid detection and account lockouts. By utilizing the
Authentication Data Model, this detection is effective for all CIM-mapped authentication
events, providing comprehensive coverage and enhancing security against these attacks.
search: >-
| tstats `security_content_summariesonly` values(Authentication.user) AS unique_user_names
dc(Authentication.user) AS unique_accounts values(Authentication.app) as app count(Authentication.user)
as total_failures from datamodel=Authentication.Authentication where Authentication.action="failure"
NOT Authentication.src IN ("-","unknown") by Authentication.src, Authentication.action,
Authentication.signature_id, sourcetype, _time span=5m | `drop_dm_object_name("Authentication")`
```fill out time buckets for 0-count events during entire search length```
| appendpipe [| timechart limit=0 span=5m count | table _time]
| fillnull value=0 unique_accounts
``` Create aggregation field & apply to all null events```
| eval counter=src+"__"+sourcetype+"__"+signature_id | eventstats values(counter)
as fnscounter | eval counter=coalesce(counter,fnscounter)
``` stats version of mvexpand ```
| stats values(app) as app values(unique_user_names) as unique_user_names values(total_failures)
as total_failures values(src) as src values(signature_id) as signature_id values(sourcetype)
as sourcetype count by counter unique_accounts _time
``` remove duplicate time buckets for each unique source```
| sort - _time unique_accounts
| dedup _time counter
```Find the outliers```
| eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std
by counter
| eval upperBound=(comp_avg+comp_std*3)
| eval isOutlier=if(unique_accounts > 30 and unique_accounts >= upperBound, 1, 0)
| replace "::ffff:*" with * in src | where isOutlier=1 | foreach *
[ eval <<FIELD>> = if(<<FIELD>>="null",null(),<<FIELD>>)]
| table _time, src, action, app, unique_accounts, unique_user_names, total_failures,
sourcetype, signature_id, counter
| `detect_password_spray_attempts_filter`
how_to_implement: >-
Ensure in-scope authentication data is CIM mapped and the src field is populated
with the source device. Also ensure fill_nullvalue is set within the macro security_content_summariesonly.
This search opporates best on a 5 minute schedule, looking back over the past 70
minutes. Configure 70 minute throttling on the two fields _time and counter.
search: "| tstats `security_content_summariesonly` values(Authentication.user) AS\
\ unique_user_names dc(Authentication.user) AS unique_accounts values(Authentication.app)\
\ as app count(Authentication.user) as total_failures from datamodel=Authentication.Authentication\
\ where Authentication.action=\"failure\" NOT Authentication.src IN (\"-\",\"unknown\"\
) by Authentication.action Authentication.app Authentication.authentication_method\
\ Authentication.dest \n Authentication.signature Authentication.signature_id Authentication.src\
\ sourcetype _time span=5m \n| `drop_dm_object_name(\"Authentication\")`\n ```fill\
\ out time buckets for 0-count events during entire search length```\n| appendpipe\
\ [| timechart limit=0 span=5m count | table _time] | fillnull value=0 unique_accounts\n\
\ ``` Create aggregation field & apply to all null events```\n| eval counter=src+\"\
__\"+sourcetype+\"__\"+signature_id | eventstats values(counter) as fnscounter\
\ | eval counter=coalesce(counter,fnscounter) \n ``` stats version of mvexpand\
\ ```\n| stats values(app) as app values(unique_user_names) as unique_user_names\
\ values(total_failures) as total_failures values(src) as src values(signature_id)\
\ as signature_id values(sourcetype) as sourcetype count by counter unique_accounts\
\ _time\n ``` remove duplicate time buckets for each unique source```\n| sort\
\ - _time unique_accounts | dedup _time counter\n ```Find the outliers```\n|\
\ eventstats avg(unique_accounts) as comp_avg , stdev(unique_accounts) as comp_std\
\ by counter | eval upperBound=(comp_avg+comp_std*3) | eval isOutlier=if(unique_accounts\
\ > 30 and unique_accounts >= upperBound, 1, 0) | replace \"::ffff:*\" with * in\
\ src | where isOutlier=1 | foreach * \n [ eval <<FIELD>> = if(<<FIELD>>=\"\
null\",null(),<<FIELD>>)] \n| table _time, src, action, app, unique_accounts, unique_user_names,\
\ total_failures, sourcetype, signature_id, counter | `detect_password_spray_attempts_filter`"
how_to_implement: 'Ensure in-scope authentication data is CIM mapped and the src field
is populated with the source device. Also ensure fill_nullvalue is set within the
macro security_content_summariesonly. This search opporates best on a 5 minute schedule,
looking back over the past 70 minutes. Configure 70 minute throttling on the two
fields _time and counter. '
known_false_positives: Unknown
references:
- https://attack.mitre.org/techniques/T1110/003/
@@ -91,7 +85,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/purplesharp_invalid_users_kerberos_xml/windows-security.log
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
@@ -1,6 +1,6 @@
name: Email files written outside of the Outlook directory
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
version: 7
version: 8
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: experimental
@@ -19,9 +19,11 @@ search: '| tstats `security_content_summariesonly` count values(Filesystem.file_
as file_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem
where (Filesystem.file_name=*.pst OR Filesystem.file_name=*.ost) Filesystem.file_path
!= "C:\\Users\\*\\My Documents\\Outlook Files\\*" Filesystem.file_path!="C:\\Users\\*\\AppData\\Local\\Microsoft\\Outlook*"
by Filesystem.action Filesystem.process_id Filesystem.file_name Filesystem.dest
| `drop_dm_object_name("Filesystem")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|
`email_files_written_outside_of_the_outlook_directory_filter`'
by Filesystem.action Filesystem.dest Filesystem.file_access_time Filesystem.file_create_time
Filesystem.file_hash Filesystem.file_modify_time Filesystem.file_name Filesystem.file_path
Filesystem.file_acl Filesystem.file_size Filesystem.process_guid Filesystem.process_id
Filesystem.user Filesystem.vendor_product | `drop_dm_object_name("Filesystem")`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`| `email_files_written_outside_of_the_outlook_directory_filter`'
how_to_implement: To successfully implement this search, you must be ingesting data
that records the file-system activity from your hosts to populate the Endpoint.Filesystem
data model node. This is typically populated via endpoint detection-and-response
@@ -1,6 +1,6 @@
name: Okta Multi-Factor Authentication Disabled
id: 7c0348ce-bdf9-45f6-8a57-c18b5976f00a
version: 6
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source:
@@ -19,8 +19,8 @@ search: '| tstats `security_content_summariesonly` count max(_time) as lastTime,
as firstTime from datamodel=Change where sourcetype="OktaIM2:log" All_Changes.object_category=User
AND All_Changes.action=modified All_Changes.command=user.mfa.factor.deactivate by
All_Changes.user All_Changes.result All_Changes.command sourcetype All_Changes.src
| `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `okta_multi_factor_authentication_disabled_filter`'
All_Changes.dest | `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `okta_multi_factor_authentication_disabled_filter`'
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
known_false_positives: Legitimate use case may require for users to disable MFA. Filter
@@ -66,7 +66,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/okta_mfa_method_disabled/okta_mfa_method_disabled.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/okta_mfa_method_disabled/okta_mfa_method_disabled.log
source: Okta
sourcetype: OktaIM2:log
@@ -1,6 +1,6 @@
name: Okta Multiple Accounts Locked Out
id: a511426e-184f-4de6-8711-cfd2af29d1e1
version: 4
version: 5
date: '2025-01-21'
author: Michael Haag, Mauricio Velazco, Splunk
data_source:
@@ -18,7 +18,7 @@ search: '| tstats `security_content_summariesonly` count max(_time) as lastTime,
as firstTime values(All_Changes.user) as user from datamodel=Change where All_Changes.change_type=AAA
All_Changes.object_category=User AND All_Changes.action=lockout AND All_Changes.command=user.account.lock
by _time span=5m All_Changes.result All_Changes.command sourcetype All_Changes.src
| where count > 5 | `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)`
All_Changes.dest | where count > 5 | `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `okta_multiple_accounts_locked_out_filter`'
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
@@ -65,7 +65,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/okta_multiple_accounts_lockout/okta_multiple_accounts_lockout.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/okta_multiple_accounts_lockout/okta_multiple_accounts_lockout.log
source: Okta
sourcetype: OktaIM2:log
@@ -1,6 +1,6 @@
name: Okta Multiple Failed MFA Requests For User
id: 826dbaae-a1e6-4c8c-b384-d16898956e73
version: 5
version: 6
date: '2025-01-21'
author: Mauricio Velazco, Splunk
data_source:
@@ -17,8 +17,8 @@ description: The following analytic identifies multiple failed multi-factor auth
search: '`okta` eventType=user.authentication.auth_via_mfa outcome.result=FAILURE
debugContext.debugData.factor!=PASSWORD_AS_FACTOR | bucket _time span=5m | stats
count min(_time) as firstTime max(_time) as lastTime values(displayMessage) values(src_ip)
as src_ip values(debugContext.debugData.factor) by _time src_user | where count
>= 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
as src_ip values(debugContext.debugData.factor) values(dest) as dest by _time src_user
| where count >= 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `okta_multiple_failed_mfa_requests_for_user_filter`'
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
@@ -63,7 +63,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/okta_multiple_failed_mfa_requests/okta_multiple_failed_mfa_requests.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/okta_multiple_failed_mfa_requests/okta_multiple_failed_mfa_requests.log
source: Okta
sourcetype: OktaIM2:log
@@ -1,6 +1,6 @@
name: Okta Multiple Users Failing To Authenticate From Ip
id: de365ffa-42f5-46b5-b43f-fa72290b8218
version: 5
version: 6
date: '2025-01-21'
author: Michael Haag, Mauricio Velazco, Splunk
data_source:
@@ -18,9 +18,10 @@ description: The following analytic identifies instances where more than 10 uniq
search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time)
as firstTime dc(Authentication.user) as unique_accounts values(Authentication.signature)
as signature values(Authentication.user) as user values(Authentication.app) as app
values(Authentication.authentication_method) as authentication_method from datamodel=Authentication
where Authentication.action="failure" AND Authentication.signature=user.session.start
by _time span=5m Authentication.src sourcetype | where unique_accounts > 9 | `drop_dm_object_name("Authentication")`
values(Authentication.authentication_method) as authentication_method values(Authentication.dest)
as dest from datamodel=Authentication where Authentication.action="failure" AND
Authentication.signature=user.session.start by _time span=5m Authentication.src
sourcetype | where unique_accounts > 9 | `drop_dm_object_name("Authentication")`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_multiple_users_failing_to_authenticate_from_ip_filter`'
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
@@ -67,7 +68,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/okta_multiple_users_from_ip/okta_multiple_users_from_ip.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.003/okta_multiple_users_from_ip/okta_multiple_users_from_ip.log
source: Okta
sourcetype: OktaIM2:log
@@ -1,6 +1,6 @@
name: Okta New API Token Created
id: c3d22720-35d3-4da4-bd0a-740d37192bd4
version: 7
version: 8
date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
@@ -18,8 +18,9 @@ data_source:
search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time)
as firstTime from datamodel=Change where All_Changes.action=created AND All_Changes.command=system.api_token.create
by _time span=5m All_Changes.user All_Changes.result All_Changes.command sourcetype
All_Changes.src All_Changes.action All_Changes.object_category | `drop_dm_object_name("All_Changes")`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_new_api_token_created_filter`'
All_Changes.src All_Changes.action All_Changes.object_category All_Changes.dest
| `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `okta_new_api_token_created_filter`'
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
known_false_positives: False positives may be present. Tune Okta and tune the analytic
@@ -63,7 +64,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.001/okta_new_api_token_created/okta_new_api_token_created.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.001/okta_new_api_token_created/okta_new_api_token_created.log
source: Okta
sourcetype: OktaIM2:log
@@ -1,6 +1,6 @@
name: Okta New Device Enrolled on Account
id: bb27cbce-d4de-432c-932f-2e206e9130fb
version: 7
version: 8
date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
@@ -18,8 +18,9 @@ data_source:
search: '| tstats `security_content_summariesonly` count max(_time) as lastTime, min(_time)
as firstTime from datamodel=Change where All_Changes.action=created All_Changes.command=device.enrollment.create
by _time span=5m All_Changes.user All_Changes.result All_Changes.command sourcetype
All_Changes.src All_Changes.action All_Changes.object_category | `drop_dm_object_name("All_Changes")`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_new_device_enrolled_on_account_filter`'
All_Changes.src All_Changes.action All_Changes.object_category All_Changes.dest
| `drop_dm_object_name("All_Changes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `okta_new_device_enrolled_on_account_filter`'
how_to_implement: The analytic leverages Okta OktaIm2 logs to be ingested using the
Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553).
known_false_positives: It is possible that the user has legitimately added a new device
@@ -63,7 +64,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.005/okta_new_device_enrolled/okta_new_device_enrolled.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.005/okta_new_device_enrolled/okta_new_device_enrolled.log
source: Okta
sourcetype: OktaIM2:log
@@ -1,6 +1,6 @@
name: Okta Successful Single Factor Authentication
id: 98f6ad4f-4325-4096-9d69-45dc8e638e82
version: 5
version: 6
date: '2025-02-10'
author: Bhavin Patel, Splunk
data_source:
@@ -18,7 +18,7 @@ search: '`okta` action=success src_user_type = User eventType = user.authentica
OR eventType = user.authentication.auth_via_mfa| stats dc(eventType) values(eventType)
as eventType values(target{}.displayName) as targets values(debugContext.debugData.url)
min(_time) as firstTime max(_time) as lastTime values(authentication_method) by
src_ip user action | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
src_ip user action dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| search targets !="Okta Verify" | `okta_successful_single_factor_authentication_filter`'
how_to_implement: This detection utilizes logs from Okta environments and requires
the ingestion of OktaIm2 logs through the Splunk Add-on for Okta Identity Cloud
@@ -66,7 +66,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/okta_single_factor_auth/okta_single_factor_auth.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078.004/okta_single_factor_auth/okta_single_factor_auth.log
source: okta_log
sourcetype: OktaIM2:log
@@ -1,6 +1,6 @@
name: Okta Suspicious Activity Reported
id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79
version: 6
version: 7
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
@@ -17,7 +17,7 @@ data_source:
- Okta
search: '`okta` eventType=user.account.report_suspicious_activity_by_enduser | stats
count min(_time) as firstTime max(_time) as lastTime values(displayMessage) by user
eventType client.userAgent.rawUserAgent client.userAgent.browser client.geographicalContext.city client.geographicalContext.country
dest src eventType client.userAgent.rawUserAgent client.userAgent.browser client.geographicalContext.city client.geographicalContext.country
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_suspicious_activity_reported_filter`'
how_to_implement: This detection utilizes logs from Okta Identity Management (IM)
environments. It requires the ingestion of OktaIm2 logs through the Splunk Add-on
@@ -64,7 +64,6 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/okta_suspicious_activity_reported_by_user/okta_suspicious_activity_reported_by_user.log
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/okta_suspicious_activity_reported_by_user/okta_suspicious_activity_reported_by_user.log
source: Okta
sourcetype: OktaIM2:log

Some files were not shown because too many files have changed in this diff Show More