mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating src files [ci skip]
This commit is contained in:
@@ -48,7 +48,7 @@ data_models =
|
||||
description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it.
|
||||
id = 2e8948a5-5239-406b-b56b-6c50ff268af4
|
||||
version = 2.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration", "Persistence"], "cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["DE.DP", "DE.AE", "DE.CM", "PR.AC"]}
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration", "Persistence"], "cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["DE.CM", "DE.AE", "DE.DP", "PR.AC"]}
|
||||
modification_date = 2018-05-21
|
||||
reference = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"]
|
||||
providing_technologies = ["AWS", "Splunk Enterprise Security"]
|
||||
@@ -241,7 +241,7 @@ data_models = ["Application_State", "Authentication", "Network_Resolution", "Net
|
||||
description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.
|
||||
id = 943773c6-c4de-4f38-89a8-0b92f98804d8
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Standard Non-Application Layer Protocol", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Standard Application Layer Protocol", "Defense Evasion"], "cis20": ["CIS 8", "CIS 9", "CIS 11", "CIS 12", "CIS 13", "CIS 3", "CIS 1"], "kill_chain_phases": ["Command and Control", "Actions on Objectives", "Delivery"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "DE.CM"]}
|
||||
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Standard Non-Application Layer Protocol", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Standard Application Layer Protocol", "Defense Evasion"], "cis20": ["CIS 8", "CIS 9", "CIS 11", "CIS 12", "CIS 13", "CIS 3", "CIS 1"], "kill_chain_phases": ["Command and Control", "Delivery", "Actions on Objectives"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "DE.CM"]}
|
||||
modification_date = 2018-07-24
|
||||
reference = ["https://attack.mitre.org/wiki/Command_and_Control", "https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware"]
|
||||
providing_technologies = ["AWS", "Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
@@ -799,7 +799,7 @@ data_models = ["Application_State", "Authentication", "Endpoint", "Network_Traff
|
||||
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more.
|
||||
id = c4b89506-fbcf-4cb7-bfd6-527e54789604
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Exploitation of Vulnerability", "System Information Discovery", "Commonly Used Port", "Command-Line Interface", "Credential Access", "Lateral Movement", "Defense Evasion", "Execution", "Remote Desktop Protocol", "Discovery"], "cis20": ["CIS 3", "CIS 18", "CIS 8", "CIS 9", "CIS 10", "CIS 12", "CIS 2", "CIS 4", "CIS 16"], "kill_chain_phases": ["Delivery", "Actions on Objectives", "Reconnaissance", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "ID.RA", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "PR.MA", "DE.CM"]}
|
||||
mappings = {"mitre_attack": ["Exploitation of Vulnerability", "Execution", "Commonly Used Port", "Command-Line Interface", "Credential Access", "Lateral Movement", "Defense Evasion", "System Information Discovery", "Remote Desktop Protocol", "Discovery"], "cis20": ["CIS 3", "CIS 18", "CIS 8", "CIS 9", "CIS 10", "CIS 12", "CIS 2", "CIS 4", "CIS 16"], "kill_chain_phases": ["Delivery", "Actions on Objectives", "Reconnaissance", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "ID.RA", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "PR.MA", "DE.CM"]}
|
||||
modification_date = 2018-12-14
|
||||
reference = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/SamSam-ransomware-chooses-Its-targets-carefully-wpna.pdf", "https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/SamSam-The-Almost-Six-Million-Dollar-Ransomware.pdf?cmp=26061"]
|
||||
providing_technologies = ["Apache", "Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Nessus", "Netbackup", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
|
||||
@@ -1147,7 +1147,7 @@ data_models = ["Email"]
|
||||
description = Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets.
|
||||
id = 31337aaa-bc22-4752-b599-ef112dq1dq7a
|
||||
version = 1.0
|
||||
mappings = {"mitre_attack": ["Valid Accounts", "Create Account"], "cis20": ["CIS 6", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["DE.DP", "DE.AE", "DE.CM"]}
|
||||
mappings = {"mitre_attack": ["Valid Accounts", "Create Account"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 6", "CIS 16"], "nist": ["DE.CM", "DE.AE", "DE.DP"]}
|
||||
modification_date = 2018-10-08
|
||||
reference = ["https://www.fbi.gov/scams-and-safety/common-fraud-schemes/internet-fraud", "https://www.fbi.gov/news/stories/2017-internet-crime-report-released-050718", "https://www.otalliance.org/news-events/press-releases/online-trust-alliance-reports-doubling-cyber-incidents-2017-0"]
|
||||
providing_technologies = ["Bro", "Microsoft Exchange", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream"]
|
||||
|
||||
+566
-566
File diff suppressed because it is too large
Load Diff
+1930
-1930
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user