updating src files [ci skip]

This commit is contained in:
research bot
2019-02-28 01:10:48 +00:00
parent b1f04e7cb9
commit 286ff000fb
3 changed files with 2500 additions and 2500 deletions
+4 -4
View File
@@ -48,7 +48,7 @@ data_models =
description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it.
id = 2e8948a5-5239-406b-b56b-6c50ff268af4
version = 2.0
mappings = {"mitre_attack": ["Command and Control", "Exfiltration", "Persistence"], "cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["DE.DP", "DE.AE", "DE.CM", "PR.AC"]}
mappings = {"mitre_attack": ["Command and Control", "Exfiltration", "Persistence"], "cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Command and Control", "Actions on Objectives"], "nist": ["DE.CM", "DE.AE", "DE.DP", "PR.AC"]}
modification_date = 2018-05-21
reference = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"]
providing_technologies = ["AWS", "Splunk Enterprise Security"]
@@ -241,7 +241,7 @@ data_models = ["Application_State", "Authentication", "Network_Resolution", "Net
description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators.
id = 943773c6-c4de-4f38-89a8-0b92f98804d8
version = 1.0
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Standard Non-Application Layer Protocol", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Standard Application Layer Protocol", "Defense Evasion"], "cis20": ["CIS 8", "CIS 9", "CIS 11", "CIS 12", "CIS 13", "CIS 3", "CIS 1"], "kill_chain_phases": ["Command and Control", "Actions on Objectives", "Delivery"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "DE.CM"]}
mappings = {"mitre_attack": ["Command and Control", "Exfiltration Over Command and Control Channel", "Standard Non-Application Layer Protocol", "Commonly Used Port", "Exfiltration Over Alternative Protocol", "Exfiltration", "Standard Application Layer Protocol", "Defense Evasion"], "cis20": ["CIS 8", "CIS 9", "CIS 11", "CIS 12", "CIS 13", "CIS 3", "CIS 1"], "kill_chain_phases": ["Command and Control", "Delivery", "Actions on Objectives"], "nist": ["ID.AM", "PR.DS", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "DE.CM"]}
modification_date = 2018-07-24
reference = ["https://attack.mitre.org/wiki/Command_and_Control", "https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware"]
providing_technologies = ["AWS", "Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
@@ -799,7 +799,7 @@ data_models = ["Application_State", "Authentication", "Endpoint", "Network_Traff
description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more.
id = c4b89506-fbcf-4cb7-bfd6-527e54789604
version = 1.0
mappings = {"mitre_attack": ["Exploitation of Vulnerability", "System Information Discovery", "Commonly Used Port", "Command-Line Interface", "Credential Access", "Lateral Movement", "Defense Evasion", "Execution", "Remote Desktop Protocol", "Discovery"], "cis20": ["CIS 3", "CIS 18", "CIS 8", "CIS 9", "CIS 10", "CIS 12", "CIS 2", "CIS 4", "CIS 16"], "kill_chain_phases": ["Delivery", "Actions on Objectives", "Reconnaissance", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "ID.RA", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "PR.MA", "DE.CM"]}
mappings = {"mitre_attack": ["Exploitation of Vulnerability", "Execution", "Commonly Used Port", "Command-Line Interface", "Credential Access", "Lateral Movement", "Defense Evasion", "System Information Discovery", "Remote Desktop Protocol", "Discovery"], "cis20": ["CIS 3", "CIS 18", "CIS 8", "CIS 9", "CIS 10", "CIS 12", "CIS 2", "CIS 4", "CIS 16"], "kill_chain_phases": ["Delivery", "Actions on Objectives", "Reconnaissance", "Installation", "Command and Control"], "nist": ["ID.AM", "PR.DS", "ID.RA", "PR.IP", "PR.PT", "PR.AC", "DE.AE", "PR.MA", "DE.CM"]}
modification_date = 2018-12-14
reference = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/SamSam-ransomware-chooses-Its-targets-carefully-wpna.pdf", "https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/SamSam-The-Almost-Six-Million-Dollar-Ransomware.pdf?cmp=26061"]
providing_technologies = ["Apache", "Bluecoat", "Bro", "Carbon Black Response", "CrowdStrike Falcon", "Linux", "Microsoft Windows", "Nessus", "Netbackup", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream", "Sysmon", "Tanium", "Ziften", "macOS"]
@@ -1147,7 +1147,7 @@ data_models = ["Email"]
description = Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets.
id = 31337aaa-bc22-4752-b599-ef112dq1dq7a
version = 1.0
mappings = {"mitre_attack": ["Valid Accounts", "Create Account"], "cis20": ["CIS 6", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "nist": ["DE.DP", "DE.AE", "DE.CM"]}
mappings = {"mitre_attack": ["Valid Accounts", "Create Account"], "kill_chain_phases": ["Actions on Objectives"], "cis20": ["CIS 6", "CIS 16"], "nist": ["DE.CM", "DE.AE", "DE.DP"]}
modification_date = 2018-10-08
reference = ["https://www.fbi.gov/scams-and-safety/common-fraud-schemes/internet-fraud", "https://www.fbi.gov/news/stories/2017-internet-crime-report-released-050718", "https://www.otalliance.org/news-events/press-releases/online-trust-alliance-reports-doubling-cyber-incidents-2017-0"]
providing_technologies = ["Bro", "Microsoft Exchange", "Palo Alto Firewall", "Splunk Enterprise Security", "Splunk Stream"]
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff