From 2b40bbedbd1763731355a2ea950eeec1c763a7ae Mon Sep 17 00:00:00 2001 From: ljstella Date: Thu, 15 Aug 2024 15:37:43 -0500 Subject: [PATCH] Deprecated Detections --- ...mally_high_aws_instances_launched_by_user.yml | 10 +++++----- ...igh_aws_instances_launched_by_user___mltk.yml | 10 +++++----- ...lly_high_aws_instances_terminated_by_user.yml | 10 +++++----- ...h_aws_instances_terminated_by_user___mltk.yml | 10 +++++----- ..._provisioning_from_previously_unseen_city.yml | 6 +++--- ...ovisioning_from_previously_unseen_country.yml | 10 +++++----- ...sioning_from_previously_unseen_ip_address.yml | 10 +++++----- ...rovisioning_from_previously_unseen_region.yml | 14 +++++++++----- ...ubernetes_cluster_sensitive_object_access.yml | 10 +++++----- ...lients_connecting_to_multiple_dns_servers.yml | 10 +++++----- ...cloud_network_access_control_list_deleted.yml | 10 +++++----- ...activity_related_to_pass_the_hash_attacks.yml | 8 ++------ ...etect_api_activity_from_users_without_mfa.yml | 10 +++++----- ...s_api_activities_from_unapproved_accounts.yml | 10 +++++----- ...ts_to_phishing_sites_leveraging_evilginx2.yml | 6 +++--- .../detect_long_dns_txt_record_response.yml | 10 +++++----- ...imikatz_via_powershell_and_eventcode_4703.yml | 10 +++++----- .../detect_new_user_aws_console_login.yml | 10 +++++----- .../detect_spike_in_aws_api_activity.yml | 10 +++++----- .../detect_spike_in_network_acl_activity.yml | 10 +++++----- .../detect_spike_in_security_group_activity.yml | 6 +++--- .../deprecated/detect_usb_device_insertion.yml | 10 +++++----- ...t_web_traffic_to_dynamic_domain_providers.yml | 10 +++++----- .../deprecated/detection_of_dns_tunnels.yml | 10 +++++----- ...ests_resolved_by_unauthorized_dns_servers.yml | 6 +++--- detections/deprecated/dns_record_changed.yml | 10 +++++----- ...ance_modified_with_previously_unseen_user.yml | 6 +++--- ...tance_started_in_previously_unseen_region.yml | 6 +++--- ...stance_started_with_previously_unseen_ami.yml | 10 +++++----- ...rted_with_previously_unseen_instance_type.yml | 6 +++--- ...tance_started_with_previously_unseen_user.yml | 6 +++--- ...tion_of_file_with_spaces_before_extension.yml | 6 +++--- ...riod_without_successful_netbackup_backups.yml | 10 +++++----- .../first_time_seen_command_line_argument.yml | 10 +++++----- ..._risk_permissions_by_resource_and_account.yml | 6 +++--- .../deprecated/gcp_detect_oauth_token_abuse.yml | 10 +++++----- .../gcp_kubernetes_cluster_scan_detection.yml | 10 +++++----- .../deprecated/identify_new_user_accounts.yml | 6 +++--- ...etect_most_active_service_accounts_by_pod.yml | 6 +++--- ..._aws_detect_rbac_authorization_by_account.yml | 10 +++++----- ...bernetes_aws_detect_sensitive_role_access.yml | 10 +++++----- ...service_accounts_forbidden_failure_access.yml | 6 +++--- ..._active_service_accounts_by_pod_namespace.yml | 10 +++++----- ...zure_detect_rbac_authorization_by_account.yml | 10 +++++----- ...etes_azure_detect_sensitive_object_access.yml | 10 +++++----- ...rnetes_azure_detect_sensitive_role_access.yml | 10 +++++----- ...service_accounts_forbidden_failure_access.yml | 10 +++++----- ...tes_azure_detect_suspicious_kubectl_calls.yml | 10 +++++----- .../kubernetes_azure_pod_scan_fingerprint.yml | 10 +++++----- .../kubernetes_azure_scan_fingerprint.yml | 10 +++++----- ...etect_most_active_service_accounts_by_pod.yml | 6 +++--- ...gcp_detect_rbac_authorizations_by_account.yml | 10 +++++----- ...rnetes_gcp_detect_sensitive_object_access.yml | 10 +++++----- ...bernetes_gcp_detect_sensitive_role_access.yml | 10 +++++----- ...service_accounts_forbidden_failure_access.yml | 6 +++--- ...netes_gcp_detect_suspicious_kubectl_calls.yml | 6 +++--- .../deprecated/monitor_dns_for_brand_abuse.yml | 10 +++++++--- .../o365_suspicious_user_email_forwarding.yml | 6 +++--- ...ght_login_failure_with_high_unknown_users.yml | 6 +++--- ...eatinsight_suspected_passwordspray_attack.yml | 2 +- .../osquery_pack___coldroot_detection.yml | 14 +++++++++----- .../deprecated/processes_created_by_netsh.yml | 14 +++++++++----- .../prohibited_software_on_endpoint.yml | 14 +++++++++----- ..._hide_files_directories_via_registry_keys.yml | 15 +++++++++------ .../remote_registry_key_modifications.yml | 14 +++++++++----- ...eduled_tasks_used_in_badrabbit_ransomware.yml | 16 ++++++++++------ .../spectre_and_meltdown_vulnerable_systems.yml | 10 +++++----- .../suspicious_changes_to_file_associations.yml | 6 +++--- .../suspicious_email___uba_anomaly.yml | 6 +++--- detections/deprecated/suspicious_file_write.yml | 6 +++--- ...picious_powershell_command_line_arguments.yml | 14 +++++++++----- ...cious_writes_to_system_volume_information.yml | 10 +++++----- .../uncommon_processes_on_endpoint.yml | 10 +++++----- .../unsigned_image_loaded_by_lsass.yml | 10 +++++----- .../unsuccessful_netbackup_backups.yml | 10 +++++----- .../web_fraud___account_harvesting.yml | 6 +++--- .../web_fraud___anomalous_user_clickspeed.yml | 6 +++--- ..._fraud___password_sharing_across_accounts.yml | 10 +++++----- .../windows_connhost_exe_started_forcefully.yml | 10 +++++----- .../windows_hosts_file_modification.yml | 6 +++--- 80 files changed, 380 insertions(+), 349 deletions(-) diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml index 02a1beea15..2edc8786fb 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user.yml @@ -1,7 +1,7 @@ name: Abnormally High AWS Instances Launched by User id: 2a9b80d3-6340-4345-b5ad-290bf5d0dac4 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: userName + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml index 29b10d287d..ce796ea01f 100644 --- a/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_launched_by_user___mltk.yml @@ -1,7 +1,7 @@ name: Abnormally High AWS Instances Launched by User - MLTK id: dec41ad5-d579-42cb-b4c6-f5dbb778bbe5 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Jason Brewer, Splunk status: deprecated type: Anomaly @@ -32,10 +32,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml index ac6a7f26c3..e0ed38a017 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user.yml @@ -1,7 +1,7 @@ name: Abnormally High AWS Instances Terminated by User id: 8d301246-fccf-45e2-a8e7-3655fd14379c -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: userName + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml index 936faf0ed0..24d38d557b 100644 --- a/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml +++ b/detections/deprecated/abnormally_high_aws_instances_terminated_by_user___mltk.yml @@ -1,7 +1,7 @@ name: Abnormally High AWS Instances Terminated by User - MLTK id: 1c02b86a-cd85-473e-a50b-014a9ac8fe3e -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Jason Brewer, Splunk status: deprecated type: Anomaly @@ -31,10 +31,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml index 0ee85cd68e..0adcebaa74 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_city.yml @@ -48,10 +48,10 @@ tags: mitre_attack_id: - T1535 observable: - - name: field - type: Unknown + - name: src_ip + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml index 972bf2dc55..364b9ab482 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_country.yml @@ -1,7 +1,7 @@ name: AWS Cloud Provisioning From Previously Unseen Country id: ceb8d3d8-06cb-49eb-beaf-829526e33ff0 -version: 1 -date: '2018-03-16' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -49,10 +49,10 @@ tags: mitre_attack_id: - T1535 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml index 58590b0009..fd2b906142 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_ip_address.yml @@ -1,7 +1,7 @@ name: AWS Cloud Provisioning From Previously Unseen IP Address id: 42e15012-ac14-4801-94f4-f1acbe64880b -version: 1 -date: '2018-03-16' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -46,10 +46,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml index 2de77ce5f2..17c217ab38 100644 --- a/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/deprecated/aws_cloud_provisioning_from_previously_unseen_region.yml @@ -1,7 +1,7 @@ name: AWS Cloud Provisioning From Previously Unseen Region id: 7971d3df-da82-4648-a6e5-b5637bea5253 -version: 1 -date: '2018-03-16' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -48,10 +48,14 @@ tags: mitre_attack_id: - T1535 observable: - - name: field - type: Unknown + - name: user + type: User Name role: - - Unknown + - Victim + - name: src_ip + type: IP Address + role: + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml index 4602746c28..d2251fcf56 100644 --- a/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml +++ b/detections/deprecated/aws_eks_kubernetes_cluster_sensitive_object_access.yml @@ -1,7 +1,7 @@ name: AWS EKS Kubernetes cluster sensitive object access id: 7f227943-2196-4d4d-8d6a-ac8cb308e61c -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml index ad4302443a..1e0cf56b4a 100644 --- a/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml +++ b/detections/deprecated/clients_connecting_to_multiple_dns_servers.yml @@ -1,7 +1,7 @@ name: Clients Connecting to Multiple DNS Servers id: 74ec6f18-604b-4202-a567-86b2066be3ce -version: 3 -date: '2020-07-21' +version: 4 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: TTP @@ -42,10 +42,10 @@ tags: mitre_attack_id: - T1048.003 observable: - - name: field - type: Unknown + - name: src + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/cloud_network_access_control_list_deleted.yml b/detections/deprecated/cloud_network_access_control_list_deleted.yml index 679c55e796..97bfd5318c 100644 --- a/detections/deprecated/cloud_network_access_control_list_deleted.yml +++ b/detections/deprecated/cloud_network_access_control_list_deleted.yml @@ -1,7 +1,7 @@ name: Cloud Network Access Control List Deleted id: 021abc51-1862-41dd-ad43-43c739c0a983 -version: 1 -date: '2020-09-08' +version: 2 +date: '2024-08-15' author: Peter Gael, Splunk status: deprecated type: Anomaly @@ -30,10 +30,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: userName + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml index 0c911874c3..9b8abca9a6 100644 --- a/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml +++ b/detections/deprecated/detect_activity_related_to_pass_the_hash_attacks.yml @@ -1,7 +1,7 @@ name: Detect Activity Related to Pass the Hash Attacks id: f5939373-8054-40ad-8c64-cec478a22a4b -version: 6 -date: '2020-10-15' +version: 7 +date: '2024-08-15' author: Bhavin Patel, Patrick Bareiss, Splunk status: deprecated type: Hunting @@ -40,10 +40,6 @@ tags: type: Hostname role: - Victim - - name: EventCode - type: Other - role: - - Other product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml index b071794296..6c3fe88e02 100644 --- a/detections/deprecated/detect_api_activity_from_users_without_mfa.yml +++ b/detections/deprecated/detect_api_activity_from_users_without_mfa.yml @@ -1,7 +1,7 @@ name: Detect API activity from users without MFA id: 4d46e8bd-4072-48e4-92db-0325889ef894 -version: 1 -date: '2018-05-17' +version: 2 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -50,10 +50,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml index 5614e6ced8..81446134ca 100644 --- a/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml +++ b/detections/deprecated/detect_aws_api_activities_from_unapproved_accounts.yml @@ -1,7 +1,7 @@ name: Detect AWS API Activities From Unapproved Accounts id: ada0f478-84a8-4641-a3f1-d82362d4bd55 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -55,10 +55,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User Name role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml index e263b72ed3..a7ae481848 100644 --- a/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml +++ b/detections/deprecated/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml @@ -50,10 +50,10 @@ tags: mitre_attack_id: - T1566.003 observable: - - name: field - type: Unknown + - name: src + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_long_dns_txt_record_response.yml b/detections/deprecated/detect_long_dns_txt_record_response.yml index a4c4066d07..e25c45c902 100644 --- a/detections/deprecated/detect_long_dns_txt_record_response.yml +++ b/detections/deprecated/detect_long_dns_txt_record_response.yml @@ -1,7 +1,7 @@ name: Detect Long DNS TXT Record Response id: 05437c07-62f5-452e-afdc-04dd44815bb9 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -40,10 +40,10 @@ tags: mitre_attack_id: - T1048.003 observable: - - name: field - type: Unknown + - name: Destination IP + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml index a404feefa4..42f4e7c4f8 100644 --- a/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml +++ b/detections/deprecated/detect_mimikatz_via_powershell_and_eventcode_4703.yml @@ -1,7 +1,7 @@ name: Detect Mimikatz Via PowerShell And EventCode 4703 id: 98917be2-bfc8-475a-8618-a9bb06575188 -version: 2 -date: '2019-02-27' +version: 3 +date: '2024-08-15' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1003.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_new_user_aws_console_login.yml b/detections/deprecated/detect_new_user_aws_console_login.yml index fb00e3d683..885f105987 100644 --- a/detections/deprecated/detect_new_user_aws_console_login.yml +++ b/detections/deprecated/detect_new_user_aws_console_login.yml @@ -1,7 +1,7 @@ name: Detect new user AWS Console Login id: ada0f478-84a8-4641-a3f3-d82362dffd75 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -37,10 +37,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_spike_in_aws_api_activity.yml b/detections/deprecated/detect_spike_in_aws_api_activity.yml index 6fc824e5ef..719d463311 100644 --- a/detections/deprecated/detect_spike_in_aws_api_activity.yml +++ b/detections/deprecated/detect_spike_in_aws_api_activity.yml @@ -1,7 +1,7 @@ name: Detect Spike in AWS API Activity id: ada0f478-84a8-4641-a3f1-d32362d4bd55 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -59,10 +59,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_spike_in_network_acl_activity.yml b/detections/deprecated/detect_spike_in_network_acl_activity.yml index 8b1cc6a0f1..8d1b7f6256 100644 --- a/detections/deprecated/detect_spike_in_network_acl_activity.yml +++ b/detections/deprecated/detect_spike_in_network_acl_activity.yml @@ -1,7 +1,7 @@ name: Detect Spike in Network ACL Activity id: ada0f478-84a8-4641-a1f1-e32372d4bd53 -version: 1 -date: '2018-05-21' +version: 2 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Anomaly @@ -46,10 +46,10 @@ tags: mitre_attack_id: - T1562.007 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_spike_in_security_group_activity.yml b/detections/deprecated/detect_spike_in_security_group_activity.yml index 448a1e74fe..5c25cbd671 100644 --- a/detections/deprecated/detect_spike_in_security_group_activity.yml +++ b/detections/deprecated/detect_spike_in_security_group_activity.yml @@ -47,10 +47,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_usb_device_insertion.yml b/detections/deprecated/detect_usb_device_insertion.yml index 4b0a6e8380..57d3fcfd25 100644 --- a/detections/deprecated/detect_usb_device_insertion.yml +++ b/detections/deprecated/detect_usb_device_insertion.yml @@ -1,7 +1,7 @@ name: Detect USB device insertion id: 104658f4-afdc-499f-9719-17a43f9826f5 -version: 1 -date: '2017-11-27' +version: 2 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -34,10 +34,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml index 7aad030ee3..0c292e1500 100644 --- a/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml +++ b/detections/deprecated/detect_web_traffic_to_dynamic_domain_providers.yml @@ -1,7 +1,7 @@ name: Detect web traffic to dynamic domain providers id: 134da869-e264-4a8f-8d7e-fcd01c18f301 -version: 2 -date: '2020-07-21' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -43,10 +43,10 @@ tags: mitre_attack_id: - T1071.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/detection_of_dns_tunnels.yml b/detections/deprecated/detection_of_dns_tunnels.yml index 6ecfdf260a..3a2068935d 100644 --- a/detections/deprecated/detection_of_dns_tunnels.yml +++ b/detections/deprecated/detection_of_dns_tunnels.yml @@ -1,7 +1,7 @@ name: Detection of DNS Tunnels id: 104658f4-afdc-499f-9719-17a43f9826f4 -version: 2 -date: '2022-02-15' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -56,10 +56,10 @@ tags: mitre_attack_id: - T1048.003 observable: - - name: field - type: Unknown + - name: src + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml index 078029a1fe..43c5407681 100644 --- a/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml +++ b/detections/deprecated/dns_query_requests_resolved_by_unauthorized_dns_servers.yml @@ -32,10 +32,10 @@ tags: mitre_attack_id: - T1071.004 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/dns_record_changed.yml b/detections/deprecated/dns_record_changed.yml index 288a4c7855..74f197f983 100644 --- a/detections/deprecated/dns_record_changed.yml +++ b/detections/deprecated/dns_record_changed.yml @@ -1,7 +1,7 @@ name: DNS record changed id: 44d3a43e-dcd5-49f7-8356-5209bb369065 -version: 3 -date: '2020-07-21' +version: 4 +date: '2024-08-15' author: Jose Hernandez, Splunk status: deprecated type: TTP @@ -48,10 +48,10 @@ tags: mitre_attack_id: - T1071.004 observable: - - name: field - type: Unknown + - name: src + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml index be0aa0099b..c8fb0bff55 100644 --- a/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_modified_with_previously_unseen_user.yml @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml index fa7e7c922f..b0f2abaada 100644 --- a/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml +++ b/detections/deprecated/ec2_instance_started_in_previously_unseen_region.yml @@ -35,10 +35,10 @@ tags: mitre_attack_id: - T1535 observable: - - name: field - type: Unknown + - name: awsRegion + type: Geo Location role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml index f4f7fec762..2da8ac4c33 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_ami.yml @@ -1,7 +1,7 @@ name: EC2 Instance Started With Previously Unseen AMI id: 347ec301-601b-48b9-81aa-9ddf9c829dd3 -version: 1 -date: '2018-03-12' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Anomaly @@ -36,10 +36,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml index ea7355984c..99e51f2d9a 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_instance_type.yml @@ -36,10 +36,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml index cf6e38c445..fc20f9c62c 100644 --- a/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml +++ b/detections/deprecated/ec2_instance_started_with_previously_unseen_user.yml @@ -37,10 +37,10 @@ tags: mitre_attack_id: - T1078.004 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml index 7519f91f51..5789c0eaf1 100644 --- a/detections/deprecated/execution_of_file_with_spaces_before_extension.yml +++ b/detections/deprecated/execution_of_file_with_spaces_before_extension.yml @@ -37,10 +37,10 @@ tags: mitre_attack_id: - T1036.003 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml index a905b68aaa..2714384690 100644 --- a/detections/deprecated/extended_period_without_successful_netbackup_backups.yml +++ b/detections/deprecated/extended_period_without_successful_netbackup_backups.yml @@ -1,7 +1,7 @@ name: Extended Period Without Successful Netbackup Backups id: a34aae96-ccf8-4aef-952c-3ea214444440 -version: 1 -date: '2017-09-12' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Hunting @@ -28,10 +28,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/first_time_seen_command_line_argument.yml b/detections/deprecated/first_time_seen_command_line_argument.yml index b29165d760..be5547908f 100644 --- a/detections/deprecated/first_time_seen_command_line_argument.yml +++ b/detections/deprecated/first_time_seen_command_line_argument.yml @@ -1,7 +1,7 @@ name: First time seen command line argument id: a1b6e73f-98d5-470f-99ac-77aacd578473 -version: 5 -date: '2020-07-21' +version: 6 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: Hunting @@ -50,10 +50,10 @@ tags: - T1059.001 - T1059.003 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml index 2e938d033f..19825f903f 100644 --- a/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml +++ b/detections/deprecated/gcp_detect_high_risk_permissions_by_resource_and_account.yml @@ -34,10 +34,10 @@ tags: mitre_attack_id: - T1078 observable: - - name: field - type: Unknown + - name: data.protoPayload.authenticationInfo.principalEmail + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/gcp_detect_oauth_token_abuse.yml b/detections/deprecated/gcp_detect_oauth_token_abuse.yml index b40eddc360..7f4f9ace51 100644 --- a/detections/deprecated/gcp_detect_oauth_token_abuse.yml +++ b/detections/deprecated/gcp_detect_oauth_token_abuse.yml @@ -1,7 +1,7 @@ name: gcp detect oauth token abuse id: a7e9f7bb-8901-4ad0-8d88-0a4ab07b1972 -version: 1 -date: '2020-09-01' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -30,10 +30,10 @@ tags: mitre_attack_id: - T1078 observable: - - name: field - type: Unknown + - name: protoPayload.status.details{}.violations{}.callerIp + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml index 8639f1dc7a..a8438aaf43 100644 --- a/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml +++ b/detections/deprecated/gcp_kubernetes_cluster_scan_detection.yml @@ -1,7 +1,7 @@ name: GCP Kubernetes cluster scan detection id: db5957ec-0144-4c56-b512-9dccbe7a2d26 -version: 1 -date: '2020-04-15' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: TTP @@ -34,10 +34,10 @@ tags: mitre_attack_id: - T1526 observable: - - name: field - type: Unknown + - name: src_ip + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/identify_new_user_accounts.yml b/detections/deprecated/identify_new_user_accounts.yml index 59dbaacef0..91aafdd651 100644 --- a/detections/deprecated/identify_new_user_accounts.yml +++ b/detections/deprecated/identify_new_user_accounts.yml @@ -29,10 +29,10 @@ tags: mitre_attack_id: - T1078.002 observable: - - name: field - type: Unknown + - name: identity + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml index 3a946be0ee..ecc5c9e585 100644 --- a/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml +++ b/detections/deprecated/kubernetes_aws_detect_most_active_service_accounts_by_pod.yml @@ -24,10 +24,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml index 4efb07706d..88588c2b68 100644 --- a/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml +++ b/detections/deprecated/kubernetes_aws_detect_rbac_authorization_by_account.yml @@ -1,7 +1,7 @@ name: Kubernetes AWS detect RBAC authorization by account id: de7264ed-3ed9-4fef-bb01-6eefc87cefe8 -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml index 516dbda7eb..7d39a1e05b 100644 --- a/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_aws_detect_sensitive_role_access.yml @@ -1,7 +1,7 @@ name: Kubernetes AWS detect sensitive role access id: b6013a7b-85e0-4a45-b051-10b252d69569 -version: 1 -date: '2020-06-23' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml index 9f0651b3a9..42b5c05586 100644 --- a/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_aws_detect_service_accounts_forbidden_failure_access.yml @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml index 2878342321..a47c5faaa9 100644 --- a/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml +++ b/detections/deprecated/kubernetes_azure_active_service_accounts_by_pod_namespace.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure active service accounts by pod namespace id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72 -version: 1 -date: '2020-05-26' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml index 2881d8d765..e32599cc0f 100644 --- a/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml +++ b/detections/deprecated/kubernetes_azure_detect_rbac_authorization_by_account.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect RBAC authorization by account id: 47af7d20-0607-4079-97d7-7a29af58b54e -version: 1 -date: '2020-05-26' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml index e93c26f489..ec893ba9e6 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_sensitive_object_access.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect sensitive object access id: 1bba382b-07fd-4ffa-b390-8002739b76e8 -version: 1 -date: '2020-05-20' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml index 38bb3710cf..6534ebeab7 100644 --- a/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_sensitive_role_access.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect sensitive role access id: f27349e5-1641-4f6a-9e68-30402be0ad4c -version: 1 -date: '2020-05-20' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml index 3a81b57338..10f8580344 100644 --- a/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_azure_detect_service_accounts_forbidden_failure_access.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect service accounts forbidden failure access id: 019690d7-420f-4da0-b320-f27b09961514 -version: 1 -date: '2020-05-20' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user.username + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml index 31c7237848..290d6a258e 100644 --- a/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml +++ b/detections/deprecated/kubernetes_azure_detect_suspicious_kubectl_calls.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure detect suspicious kubectl calls id: 4b6d1ba8-0000-4cec-87e6-6cbbd71651b5 -version: 1 -date: '2020-05-26' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -28,10 +28,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml index 4c09f89d36..ef66c8e12a 100644 --- a/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml +++ b/detections/deprecated/kubernetes_azure_pod_scan_fingerprint.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure pod scan fingerprint id: 86aad3e0-732f-4f66-bbbc-70df448e461d -version: 1 -date: '2020-05-20' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -25,10 +25,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml index dbd4220f90..9d501762dd 100644 --- a/detections/deprecated/kubernetes_azure_scan_fingerprint.yml +++ b/detections/deprecated/kubernetes_azure_scan_fingerprint.yml @@ -1,7 +1,7 @@ name: Kubernetes Azure scan fingerprint id: c5e5bd5c-1013-4841-8b23-e7b3253c840a -version: 1 -date: '2020-05-19' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -27,10 +27,10 @@ tags: mitre_attack_id: - T1526 observable: - - name: field - type: Unknown + - name: sourceIPs{} + type: IP Address role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml index 46481a7a42..eb1617744d 100644 --- a/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml +++ b/detections/deprecated/kubernetes_gcp_detect_most_active_service_accounts_by_pod.yml @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml index c8e0ef24ec..c944e6a2c8 100644 --- a/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml +++ b/detections/deprecated/kubernetes_gcp_detect_rbac_authorizations_by_account.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect RBAC authorizations by account id: 99487de3-7192-4b41-939d-fbe9acfb1340 -version: 1 -date: '2020-07-11' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml index f237528f37..c32a2b9b1a 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_object_access.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect sensitive object access id: bdb6d596-86a0-4aba-8369-418ae8b9963a -version: 1 -date: '2020-07-11' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml index 84d7db1a83..dde0aacc73 100644 --- a/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_sensitive_role_access.yml @@ -1,7 +1,7 @@ name: Kubernetes GCP detect sensitive role access id: a46923f6-36b9-4806-a681-31f314907c30 -version: 1 -date: '2020-07-11' +version: 2 +date: '2024-08-15' author: Rod Soto, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml index 4904afdb5c..30d4b1eff7 100644 --- a/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml +++ b/detections/deprecated/kubernetes_gcp_detect_service_accounts_forbidden_failure_access.yml @@ -28,10 +28,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml index cbdfd5e008..bd60e36559 100644 --- a/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml +++ b/detections/deprecated/kubernetes_gcp_detect_suspicious_kubectl_calls.yml @@ -27,10 +27,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/monitor_dns_for_brand_abuse.yml b/detections/deprecated/monitor_dns_for_brand_abuse.yml index 8acf3ec95c..46266f7e01 100644 --- a/detections/deprecated/monitor_dns_for_brand_abuse.yml +++ b/detections/deprecated/monitor_dns_for_brand_abuse.yml @@ -29,10 +29,14 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: query + type: Other role: - - Unknown + - Victim + - name: IPs + type: IP Address + role: + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/o365_suspicious_user_email_forwarding.yml b/detections/deprecated/o365_suspicious_user_email_forwarding.yml index b9eda6557b..69cc73978f 100644 --- a/detections/deprecated/o365_suspicious_user_email_forwarding.yml +++ b/detections/deprecated/o365_suspicious_user_email_forwarding.yml @@ -1,7 +1,7 @@ name: O365 Suspicious User Email Forwarding id: f8dfe015-dbb3-4569-ba75-b13787e06aa4 -version: 1 -date: '2020-12-16' +version: 2 +date: '2024-08-15' author: Patrick Bareiss, Splunk status: deprecated type: Anomaly @@ -38,7 +38,7 @@ tags: - name: ForwardingSmtpAddress type: Email Address role: - - Other + - Attacker product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml index a91c807f39..35e8ad3eac 100644 --- a/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml +++ b/detections/deprecated/okta_threatinsight_login_failure_with_high_unknown_users.yml @@ -30,10 +30,10 @@ tags: - T1078.001 - T1110.004 observable: - - name: outcome.reason - type: Other + - name: user + type: User role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml index 0ab7b85ded..6dbf63e41c 100644 --- a/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml +++ b/detections/deprecated/okta_threatinsight_suspected_passwordspray_attack.yml @@ -34,7 +34,7 @@ tags: - name: outcome.reason type: Other role: - - Other + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/osquery_pack___coldroot_detection.yml b/detections/deprecated/osquery_pack___coldroot_detection.yml index 14ccc214ee..cacc2e6048 100644 --- a/detections/deprecated/osquery_pack___coldroot_detection.yml +++ b/detections/deprecated/osquery_pack___coldroot_detection.yml @@ -1,7 +1,7 @@ name: Osquery pack - ColdRoot detection id: a6fffe5e-05c3-4c04-badc-887607fbb8dc -version: 1 -date: '2019-01-29' +version: 2 +date: '2024-08-15' author: Rico Valdez, Splunk status: deprecated type: TTP @@ -25,10 +25,14 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: host + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/processes_created_by_netsh.yml b/detections/deprecated/processes_created_by_netsh.yml index 9caca611a1..53d46eb369 100644 --- a/detections/deprecated/processes_created_by_netsh.yml +++ b/detections/deprecated/processes_created_by_netsh.yml @@ -1,7 +1,7 @@ name: Processes created by netsh id: b89919ed-fe5f-492c-b139-95dbb162041e -version: 5 -date: '2020-11-23' +version: 6 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -43,10 +43,14 @@ tags: mitre_attack_id: - T1562.004 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/prohibited_software_on_endpoint.yml b/detections/deprecated/prohibited_software_on_endpoint.yml index 27b76ed896..49935603d1 100644 --- a/detections/deprecated/prohibited_software_on_endpoint.yml +++ b/detections/deprecated/prohibited_software_on_endpoint.yml @@ -1,7 +1,7 @@ name: Prohibited Software On Endpoint id: a51bfe1a-94f0-48cc-b4e4-b6ae50145893 -version: 2 -date: '2019-10-11' +version: 3 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Hunting @@ -34,10 +34,14 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml index 26ee538d51..5b575ca1db 100644 --- a/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml +++ b/detections/deprecated/reg_exe_used_to_hide_files_directories_via_registry_keys.yml @@ -1,7 +1,7 @@ name: Reg exe used to hide files directories via registry keys id: 61a7d1e6-f5d4-41d9-a9be-39a1ffe69459 -version: 2 -date: '2019-02-27' +version: 3 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -32,17 +32,20 @@ tags: - Windows Defense Evasion Tactics - Suspicious Windows Registry Activities - Windows Persistence Techniques - asset_type: Endpoint confidence: 50 impact: 50 message: tbd mitre_attack_id: - T1564.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/remote_registry_key_modifications.yml b/detections/deprecated/remote_registry_key_modifications.yml index 8c8435ee89..ded756a184 100644 --- a/detections/deprecated/remote_registry_key_modifications.yml +++ b/detections/deprecated/remote_registry_key_modifications.yml @@ -1,7 +1,7 @@ name: Remote Registry Key modifications id: c9f4b923-f8af-4155-b697-1354f5dcbc5e -version: 3 -date: '2020-03-02' +version: 4 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -31,10 +31,14 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim + - name: dest + type: Hostname + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml index e7d235b110..ea81ef6de4 100644 --- a/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml +++ b/detections/deprecated/scheduled_tasks_used_in_badrabbit_ransomware.yml @@ -1,7 +1,7 @@ name: Scheduled tasks used in BadRabbit ransomware id: 1297fb80-f42a-4b4a-9c8b-78c066437cf6 -version: 3 -date: '2020-07-21' +version: 4 +date: '2024-08-15' author: Bhavin Patel, Splunk status: deprecated type: TTP @@ -13,7 +13,7 @@ data_source: search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process= "*create*" OR Processes.process= - "*delete*") by Processes.parent_process Processes.process_name Processes.user | + "*delete*") by Processes.parent_process Processes.process_name Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)` | search (process=*rhaegal* OR process=*drogon* OR *viserion_*) | `scheduled_tasks_used_in_badrabbit_ransomware_filter`' how_to_implement: The detection is based on data that originates from Endpoint Detection @@ -37,10 +37,14 @@ tags: mitre_attack_id: - T1053.005 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim + - name: dest + type: Hostname + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml index 34aa5f5d0e..b8a24e348b 100644 --- a/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml +++ b/detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml @@ -1,7 +1,7 @@ name: Spectre and Meltdown Vulnerable Systems id: 354be8e0-32cd-4da0-8c47-796de13b60ea -version: 1 -date: '2017-01-07' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: TTP @@ -28,10 +28,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_changes_to_file_associations.yml b/detections/deprecated/suspicious_changes_to_file_associations.yml index 08ca5c2989..3365f815e9 100644 --- a/detections/deprecated/suspicious_changes_to_file_associations.yml +++ b/detections/deprecated/suspicious_changes_to_file_associations.yml @@ -43,10 +43,10 @@ tags: mitre_attack_id: - T1546.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_email___uba_anomaly.yml b/detections/deprecated/suspicious_email___uba_anomaly.yml index 77ca06d485..4c05d4bf7c 100644 --- a/detections/deprecated/suspicious_email___uba_anomaly.yml +++ b/detections/deprecated/suspicious_email___uba_anomaly.yml @@ -35,10 +35,10 @@ tags: mitre_attack_id: - T1566 observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_file_write.yml b/detections/deprecated/suspicious_file_write.yml index b7a2b0c9ef..8388c3087d 100644 --- a/detections/deprecated/suspicious_file_write.yml +++ b/detections/deprecated/suspicious_file_write.yml @@ -37,10 +37,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_powershell_command_line_arguments.yml b/detections/deprecated/suspicious_powershell_command_line_arguments.yml index 572bb38339..1d02ccddfa 100644 --- a/detections/deprecated/suspicious_powershell_command_line_arguments.yml +++ b/detections/deprecated/suspicious_powershell_command_line_arguments.yml @@ -1,7 +1,7 @@ name: Suspicious Powershell Command-Line Arguments id: 2cdb91d2-542c-497f-b252-be495e71f38c -version: 6 -date: '2021-01-19' +version: 7 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: TTP @@ -44,10 +44,14 @@ tags: mitre_attack_id: - T1059.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim + - name: user + type: User + role: + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/suspicious_writes_to_system_volume_information.yml b/detections/deprecated/suspicious_writes_to_system_volume_information.yml index c3ea9c5edf..6ef978bb17 100644 --- a/detections/deprecated/suspicious_writes_to_system_volume_information.yml +++ b/detections/deprecated/suspicious_writes_to_system_volume_information.yml @@ -1,7 +1,7 @@ name: Suspicious writes to System Volume Information id: cd6297cd-2bdd-4aa1-84aa-5d2f84228fac -version: 2 -date: '2020-07-22' +version: 3 +date: '2024-08-15' author: Rico Valdez, Splunk status: deprecated type: Hunting @@ -30,10 +30,10 @@ tags: mitre_attack_id: - T1036 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/uncommon_processes_on_endpoint.yml b/detections/deprecated/uncommon_processes_on_endpoint.yml index 18a30cc4de..0a55effb55 100644 --- a/detections/deprecated/uncommon_processes_on_endpoint.yml +++ b/detections/deprecated/uncommon_processes_on_endpoint.yml @@ -1,7 +1,7 @@ name: Uncommon Processes On Endpoint id: 29ccce64-a10c-4389-a45f-337cb29ba1f7 -version: 4 -date: '2020-07-22' +version: 5 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Hunting @@ -36,10 +36,10 @@ tags: mitre_attack_id: - T1204.002 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/unsigned_image_loaded_by_lsass.yml b/detections/deprecated/unsigned_image_loaded_by_lsass.yml index 5a926b6aff..226b011c06 100644 --- a/detections/deprecated/unsigned_image_loaded_by_lsass.yml +++ b/detections/deprecated/unsigned_image_loaded_by_lsass.yml @@ -1,7 +1,7 @@ name: Unsigned Image Loaded by LSASS id: 56ef054c-76ef-45f9-af4a-a634695dcd65 -version: 1 -date: '2019-12-06' +version: 2 +date: '2024-08-15' author: Patrick Bareiss, Splunk status: deprecated type: TTP @@ -33,10 +33,10 @@ tags: mitre_attack_id: - T1003.001 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/unsuccessful_netbackup_backups.yml b/detections/deprecated/unsuccessful_netbackup_backups.yml index b8457b91e5..60af44671d 100644 --- a/detections/deprecated/unsuccessful_netbackup_backups.yml +++ b/detections/deprecated/unsuccessful_netbackup_backups.yml @@ -1,7 +1,7 @@ name: Unsuccessful Netbackup backups id: a34aae96-ccf8-4aaa-952c-3ea21444444f -version: 1 -date: '2017-09-12' +version: 2 +date: '2024-08-15' author: David Dorsey, Splunk status: deprecated type: Hunting @@ -26,10 +26,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/web_fraud___account_harvesting.yml b/detections/deprecated/web_fraud___account_harvesting.yml index 4cf762f1ac..2fa37d3ae8 100644 --- a/detections/deprecated/web_fraud___account_harvesting.yml +++ b/detections/deprecated/web_fraud___account_harvesting.yml @@ -45,10 +45,10 @@ tags: mitre_attack_id: - T1136 observable: - - name: field - type: Unknown + - name: src_user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml index 37dc1e7655..aa02229a5b 100644 --- a/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml +++ b/detections/deprecated/web_fraud___anomalous_user_clickspeed.yml @@ -41,10 +41,10 @@ tags: mitre_attack_id: - T1078 observable: - - name: field - type: Unknown + - name: session_id + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml index 0819ba7af8..9c212c0df9 100644 --- a/detections/deprecated/web_fraud___password_sharing_across_accounts.yml +++ b/detections/deprecated/web_fraud___password_sharing_across_accounts.yml @@ -1,7 +1,7 @@ name: Web Fraud - Password Sharing Across Accounts id: 31337a1a-53b9-4e05-96e9-55c934cb71d3 -version: 1 -date: '2018-10-08' +version: 2 +date: '2024-08-15' author: Jim Apger, Splunk status: deprecated type: Anomaly @@ -34,10 +34,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: user + type: User role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/windows_connhost_exe_started_forcefully.yml b/detections/deprecated/windows_connhost_exe_started_forcefully.yml index 173ee8ff8a..8f3fcab9fe 100644 --- a/detections/deprecated/windows_connhost_exe_started_forcefully.yml +++ b/detections/deprecated/windows_connhost_exe_started_forcefully.yml @@ -1,7 +1,7 @@ name: Windows connhost exe started forcefully id: c114aaca-68ee-41c2-ad8c-32bf21db8769 -version: 1 -date: '2020-11-06' +version: 2 +date: '2024-08-15' author: Rod Soto, Jose Hernandez, Splunk status: deprecated type: TTP @@ -39,10 +39,10 @@ tags: mitre_attack_id: - T1059.003 observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security diff --git a/detections/deprecated/windows_hosts_file_modification.yml b/detections/deprecated/windows_hosts_file_modification.yml index ffa7d52961..b9b1217283 100644 --- a/detections/deprecated/windows_hosts_file_modification.yml +++ b/detections/deprecated/windows_hosts_file_modification.yml @@ -31,10 +31,10 @@ tags: impact: 50 message: tbd observable: - - name: field - type: Unknown + - name: dest + type: Hostname role: - - Unknown + - Victim product: - Splunk Enterprise - Splunk Enterprise Security