mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Added missing nist and cis20 fields to 3 experimental detections.
This commit is contained in:
@@ -34,6 +34,7 @@ tags:
|
||||
analytic_story:
|
||||
- IcedID
|
||||
automated_detection_testing: passed
|
||||
cis20: []
|
||||
confidence: 70
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -47,6 +48,7 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1562.001
|
||||
- T1562
|
||||
nist: []
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
|
||||
@@ -27,6 +27,7 @@ references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Insider Threat
|
||||
cis20: []
|
||||
confidence: 80
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -39,6 +40,7 @@ tags:
|
||||
message: High number of files copied
|
||||
mitre_attack_id:
|
||||
- T1048.003
|
||||
nist: []
|
||||
observable:
|
||||
- name: dest_user_id
|
||||
type: User
|
||||
|
||||
@@ -35,6 +35,7 @@ tags:
|
||||
analytic_story:
|
||||
- Clop Ransomware
|
||||
- Insider Threat
|
||||
cis20: []
|
||||
confidence: 80
|
||||
context:
|
||||
- Source:Endpoint
|
||||
@@ -47,6 +48,7 @@ tags:
|
||||
message: High frequency file deletion activity detected on host $Computer$
|
||||
mitre_attack_id:
|
||||
- T1485
|
||||
nist: []
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
|
||||
Reference in New Issue
Block a user