Deprecated Detections

This commit is contained in:
ljstella
2024-08-15 15:37:43 -05:00
parent 3e9684660f
commit 2b40bbedbd
80 changed files with 380 additions and 349 deletions
@@ -1,7 +1,7 @@
name: Abnormally High AWS Instances Launched by User
id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: userName
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High AWS Instances Launched by User - MLTK
id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Jason Brewer, Splunk
status: deprecated
type: Anomaly
@@ -32,10 +32,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High AWS Instances Terminated by User
id: 8d301246-fccf-45e2-a8e7-3655fd14379c
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: userName
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High AWS Instances Terminated by User - MLTK
id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Jason Brewer, Splunk
status: deprecated
type: Anomaly
@@ -31,10 +31,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -48,10 +48,10 @@ tags:
mitre_attack_id:
- T1535
observable:
- name: field
type: Unknown
- name: src_ip
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Cloud Provisioning From Previously Unseen Country
id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0
version: 1
date: '2018-03-16'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -49,10 +49,10 @@ tags:
mitre_attack_id:
- T1535
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Cloud Provisioning From Previously Unseen IP Address
id: 42e15012-ac14-4801-94f4-f1acbe64880b
version: 1
date: '2018-03-16'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -46,10 +46,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Cloud Provisioning From Previously Unseen Region
id: 7971d3df-da82-4648-a6e5-b5637bea5253
version: 1
date: '2018-03-16'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -48,10 +48,14 @@ tags:
mitre_attack_id:
- T1535
observable:
- name: field
type: Unknown
- name: user
type: User Name
role:
- Unknown
- Victim
- name: src_ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS EKS Kubernetes cluster sensitive object access
id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Clients Connecting to Multiple DNS Servers
id: 74ec6f18-604b-4202-a567-86b2066be3ce
version: 3
date: '2020-07-21'
version: 4
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: TTP
@@ -42,10 +42,10 @@ tags:
mitre_attack_id:
- T1048.003
observable:
- name: field
type: Unknown
- name: src
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Cloud Network Access Control List Deleted
id: 021abc51-1862-41dd-ad43-43c739c0a983
version: 1
date: '2020-09-08'
version: 2
date: '2024-08-15'
author: Peter Gael, Splunk
status: deprecated
type: Anomaly
@@ -30,10 +30,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: userName
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Activity Related to Pass the Hash Attacks
id: f5939373-8054-40ad-8c64-cec478a22a4b
version: 6
date: '2020-10-15'
version: 7
date: '2024-08-15'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: deprecated
type: Hunting
@@ -40,10 +40,6 @@ tags:
type: Hostname
role:
- Victim
- name: EventCode
type: Other
role:
- Other
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect API activity from users without MFA
id: 4d46e8bd-4072-48e4-92db-0325889ef894
version: 1
date: '2018-05-17'
version: 2
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -50,10 +50,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect AWS API Activities From Unapproved Accounts
id: ada0f478-84a8-4641-a3f1-d82362d4bd55
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -55,10 +55,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User Name
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -50,10 +50,10 @@ tags:
mitre_attack_id:
- T1566.003
observable:
- name: field
type: Unknown
- name: src
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Long DNS TXT Record Response
id: 05437c07-62f5-452e-afdc-04dd44815bb9
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -40,10 +40,10 @@ tags:
mitre_attack_id:
- T1048.003
observable:
- name: field
type: Unknown
- name: Destination IP
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Mimikatz Via PowerShell And EventCode 4703
id: 98917be2-bfc8-475a-8618-a9bb06575188
version: 2
date: '2019-02-27'
version: 3
date: '2024-08-15'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1003.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect new user AWS Console Login
id: ada0f478-84a8-4641-a3f3-d82362dffd75
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -37,10 +37,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Spike in AWS API Activity
id: ada0f478-84a8-4641-a3f1-d32362d4bd55
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -59,10 +59,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Spike in Network ACL Activity
id: ada0f478-84a8-4641-a1f1-e32372d4bd53
version: 1
date: '2018-05-21'
version: 2
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Anomaly
@@ -46,10 +46,10 @@ tags:
mitre_attack_id:
- T1562.007
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -47,10 +47,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect USB device insertion
id: 104658f4-afdc-499f-9719-17a43f9826f5
version: 1
date: '2017-11-27'
version: 2
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -34,10 +34,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect web traffic to dynamic domain providers
id: 134da869-e264-4a8f-8d7e-fcd01c18f301
version: 2
date: '2020-07-21'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -43,10 +43,10 @@ tags:
mitre_attack_id:
- T1071.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detection of DNS Tunnels
id: 104658f4-afdc-499f-9719-17a43f9826f4
version: 2
date: '2022-02-15'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -56,10 +56,10 @@ tags:
mitre_attack_id:
- T1048.003
observable:
- name: field
type: Unknown
- name: src
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -32,10 +32,10 @@ tags:
mitre_attack_id:
- T1071.004
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
+5 -5
View File
@@ -1,7 +1,7 @@
name: DNS record changed
id: 44d3a43e-dcd5-49f7-8356-5209bb369065
version: 3
date: '2020-07-21'
version: 4
date: '2024-08-15'
author: Jose Hernandez, Splunk
status: deprecated
type: TTP
@@ -48,10 +48,10 @@ tags:
mitre_attack_id:
- T1071.004
observable:
- name: field
type: Unknown
- name: src
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -35,10 +35,10 @@ tags:
mitre_attack_id:
- T1535
observable:
- name: field
type: Unknown
- name: awsRegion
type: Geo Location
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: EC2 Instance Started With Previously Unseen AMI
id: 347ec301-601b-48b9-81aa-9ddf9c829dd3
version: 1
date: '2018-03-12'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Anomaly
@@ -36,10 +36,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -36,10 +36,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -37,10 +37,10 @@ tags:
mitre_attack_id:
- T1078.004
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -37,10 +37,10 @@ tags:
mitre_attack_id:
- T1036.003
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Extended Period Without Successful Netbackup Backups
id: a34aae96-ccf8-4aef-952c-3ea214444440
version: 1
date: '2017-09-12'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Hunting
@@ -28,10 +28,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: First time seen command line argument
id: a1b6e73f-98d5-470f-99ac-77aacd578473
version: 5
date: '2020-07-21'
version: 6
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: Hunting
@@ -50,10 +50,10 @@ tags:
- T1059.001
- T1059.003
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -34,10 +34,10 @@ tags:
mitre_attack_id:
- T1078
observable:
- name: field
type: Unknown
- name: data.protoPayload.authenticationInfo.principalEmail
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: gcp detect oauth token abuse
id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972
version: 1
date: '2020-09-01'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -30,10 +30,10 @@ tags:
mitre_attack_id:
- T1078
observable:
- name: field
type: Unknown
- name: protoPayload.status.details{}.violations{}.callerIp
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: GCP Kubernetes cluster scan detection
id: db5957ec-0144-4c56-b512-9dccbe7a2d26
version: 1
date: '2020-04-15'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: TTP
@@ -34,10 +34,10 @@ tags:
mitre_attack_id:
- T1526
observable:
- name: field
type: Unknown
- name: src_ip
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -29,10 +29,10 @@ tags:
mitre_attack_id:
- T1078.002
observable:
- name: field
type: Unknown
- name: identity
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -24,10 +24,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes AWS detect RBAC authorization by account
id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes AWS detect sensitive role access
id: b6013a7b-85e0-4a45-b051-10b252d69569
version: 1
date: '2020-06-23'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure active service accounts by pod namespace
id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72
version: 1
date: '2020-05-26'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect RBAC authorization by account
id: 47af7d20-0607-4079-97d7-7a29af58b54e
version: 1
date: '2020-05-26'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect sensitive object access
id: 1bba382b-07fd-4ffa-b390-8002739b76e8
version: 1
date: '2020-05-20'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect sensitive role access
id: f27349e5-1641-4f6a-9e68-30402be0ad4c
version: 1
date: '2020-05-20'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect service accounts forbidden failure access
id: 019690d7-420f-4da0-b320-f27b09961514
version: 1
date: '2020-05-20'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user.username
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure detect suspicious kubectl calls
id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5
version: 1
date: '2020-05-26'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -28,10 +28,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure pod scan fingerprint
id: 86aad3e0-732f-4f66-bbbc-70df448e461d
version: 1
date: '2020-05-20'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -25,10 +25,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes Azure scan fingerprint
id: c5e5bd5c-1013-4841-8b23-e7b3253c840a
version: 1
date: '2020-05-19'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -27,10 +27,10 @@ tags:
mitre_attack_id:
- T1526
observable:
- name: field
type: Unknown
- name: sourceIPs{}
type: IP Address
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect RBAC authorizations by account
id: 99487de3-7192-4b41-939d-fbe9acfb1340
version: 1
date: '2020-07-11'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect sensitive object access
id: bdb6d596-86a0-4aba-8369-418ae8b9963a
version: 1
date: '2020-07-11'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Kubernetes GCP detect sensitive role access
id: a46923f6-36b9-4806-a681-31f314907c30
version: 1
date: '2020-07-11'
version: 2
date: '2024-08-15'
author: Rod Soto, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -28,10 +28,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -27,10 +27,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -29,10 +29,14 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: query
type: Other
role:
- Unknown
- Victim
- name: IPs
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: O365 Suspicious User Email Forwarding
id: f8dfe015-dbb3-4569-ba75-b13787e06aa4
version: 1
date: '2020-12-16'
version: 2
date: '2024-08-15'
author: Patrick Bareiss, Splunk
status: deprecated
type: Anomaly
@@ -38,7 +38,7 @@ tags:
- name: ForwardingSmtpAddress
type: Email Address
role:
- Other
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -30,10 +30,10 @@ tags:
- T1078.001
- T1110.004
observable:
- name: outcome.reason
type: Other
- name: user
type: User
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -34,7 +34,7 @@ tags:
- name: outcome.reason
type: Other
role:
- Other
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Osquery pack - ColdRoot detection
id: a6fffe5e-05c3-4c04-badc-887607fbb8dc
version: 1
date: '2019-01-29'
version: 2
date: '2024-08-15'
author: Rico Valdez, Splunk
status: deprecated
type: TTP
@@ -25,10 +25,14 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: host
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Processes created by netsh
id: b89919ed-fe5f-492c-b139-95dbb162041e
version: 5
date: '2020-11-23'
version: 6
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -43,10 +43,14 @@ tags:
mitre_attack_id:
- T1562.004
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Prohibited Software On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893
version: 2
date: '2019-10-11'
version: 3
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Hunting
@@ -34,10 +34,14 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Reg exe used to hide files directories via registry keys
id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459
version: 2
date: '2019-02-27'
version: 3
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -32,17 +32,20 @@ tags:
- Windows Defense Evasion Tactics
- Suspicious Windows Registry Activities
- Windows Persistence Techniques
asset_type: Endpoint
confidence: 50
impact: 50
message: tbd
mitre_attack_id:
- T1564.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Remote Registry Key modifications
id: c9f4b923-f8af-4155-b697-1354f5dcbc5e
version: 3
date: '2020-03-02'
version: 4
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -31,10 +31,14 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Scheduled tasks used in BadRabbit ransomware
id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6
version: 3
date: '2020-07-21'
version: 4
date: '2024-08-15'
author: Bhavin Patel, Splunk
status: deprecated
type: TTP
@@ -13,7 +13,7 @@ data_source:
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime values(Processes.process) as process from datamodel=Endpoint.Processes
where Processes.process_name=schtasks.exe (Processes.process= "*create*" OR Processes.process=
"*delete*") by Processes.parent_process Processes.process_name Processes.user |
"*delete*") by Processes.parent_process Processes.process_name Processes.user Processes.dest |
`drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`
| search (process=*rhaegal* OR process=*drogon* OR *viserion_*) | `scheduled_tasks_used_in_badrabbit_ransomware_filter`'
how_to_implement: The detection is based on data that originates from Endpoint Detection
@@ -37,10 +37,14 @@ tags:
mitre_attack_id:
- T1053.005
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
- name: dest
type: Hostname
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Spectre and Meltdown Vulnerable Systems
id: 354be8e0-32cd-4da0-8c47-796de13b60ea
version: 1
date: '2017-01-07'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: TTP
@@ -28,10 +28,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -43,10 +43,10 @@ tags:
mitre_attack_id:
- T1546.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -35,10 +35,10 @@ tags:
mitre_attack_id:
- T1566
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -37,10 +37,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Suspicious Powershell Command-Line Arguments
id: 2cdb91d2-542c-497f-b252-be495e71f38c
version: 6
date: '2021-01-19'
version: 7
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: TTP
@@ -44,10 +44,14 @@ tags:
mitre_attack_id:
- T1059.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Suspicious writes to System Volume Information
id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac
version: 2
date: '2020-07-22'
version: 3
date: '2024-08-15'
author: Rico Valdez, Splunk
status: deprecated
type: Hunting
@@ -30,10 +30,10 @@ tags:
mitre_attack_id:
- T1036
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Uncommon Processes On Endpoint
id: 29ccce64-a10c-4389-a45f-337cb29ba1f7
version: 4
date: '2020-07-22'
version: 5
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Hunting
@@ -36,10 +36,10 @@ tags:
mitre_attack_id:
- T1204.002
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Unsigned Image Loaded by LSASS
id: 56ef054c-76ef-45f9-af4a-a634695dcd65
version: 1
date: '2019-12-06'
version: 2
date: '2024-08-15'
author: Patrick Bareiss, Splunk
status: deprecated
type: TTP
@@ -33,10 +33,10 @@ tags:
mitre_attack_id:
- T1003.001
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Unsuccessful Netbackup backups
id: a34aae96-ccf8-4aaa-952c-3ea21444444f
version: 1
date: '2017-09-12'
version: 2
date: '2024-08-15'
author: David Dorsey, Splunk
status: deprecated
type: Hunting
@@ -26,10 +26,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -45,10 +45,10 @@ tags:
mitre_attack_id:
- T1136
observable:
- name: field
type: Unknown
- name: src_user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -41,10 +41,10 @@ tags:
mitre_attack_id:
- T1078
observable:
- name: field
type: Unknown
- name: session_id
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Web Fraud - Password Sharing Across Accounts
id: 31337a1a-53b9-4e05-96e9-55c934cb71d3
version: 1
date: '2018-10-08'
version: 2
date: '2024-08-15'
author: Jim Apger, Splunk
status: deprecated
type: Anomaly
@@ -34,10 +34,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: user
type: User
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows connhost exe started forcefully
id: c114aaca-68ee-41c2-ad8c-32bf21db8769
version: 1
date: '2020-11-06'
version: 2
date: '2024-08-15'
author: Rod Soto, Jose Hernandez, Splunk
status: deprecated
type: TTP
@@ -39,10 +39,10 @@ tags:
mitre_attack_id:
- T1059.003
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -31,10 +31,10 @@ tags:
impact: 50
message: tbd
observable:
- name: field
type: Unknown
- name: dest
type: Hostname
role:
- Unknown
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security