Added missing nist and cis20 fields to 3 experimental detections.

This commit is contained in:
pyth0n1c
2022-10-04 16:54:34 -07:00
parent e033d17e23
commit 3941a240b2
3 changed files with 6 additions and 0 deletions
@@ -34,6 +34,7 @@ tags:
analytic_story:
- IcedID
automated_detection_testing: passed
cis20: []
confidence: 70
context:
- Source:Endpoint
@@ -47,6 +48,7 @@ tags:
mitre_attack_id:
- T1562.001
- T1562
nist: []
observable:
- name: dest
type: Hostname
@@ -27,6 +27,7 @@ references: []
tags:
analytic_story:
- Insider Threat
cis20: []
confidence: 80
context:
- Source:Endpoint
@@ -39,6 +40,7 @@ tags:
message: High number of files copied
mitre_attack_id:
- T1048.003
nist: []
observable:
- name: dest_user_id
type: User
@@ -35,6 +35,7 @@ tags:
analytic_story:
- Clop Ransomware
- Insider Threat
cis20: []
confidence: 80
context:
- Source:Endpoint
@@ -47,6 +48,7 @@ tags:
message: High frequency file deletion activity detected on host $Computer$
mitre_attack_id:
- T1485
nist: []
observable:
- name: user
type: User