mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge pull request #1725 from splunk/CARS_UPDATE_MITRE_ID_B7
Cars update mitre id b7
This commit is contained in:
+1
@@ -56,6 +56,7 @@ tags:
|
||||
$dest$ executed by user $user$.
|
||||
mitre_attack_id:
|
||||
- T1059.001
|
||||
- T1059
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -32,6 +32,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1127.001
|
||||
- T1127
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -64,6 +64,7 @@ tags:
|
||||
message: A registry activity in $registry_path$ related to persistence in host $dest$
|
||||
mitre_attack_id:
|
||||
- T1547.001
|
||||
- T1547
|
||||
nist:
|
||||
- PR.PT
|
||||
- DE.CM
|
||||
|
||||
@@ -33,6 +33,7 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1485
|
||||
- T1070.004
|
||||
- T1070
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -31,6 +31,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1036.003
|
||||
- T1036
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -47,6 +47,7 @@ tags:
|
||||
message: Wevtutil.exe being used to clear Event Logs on $dest$ by $user$
|
||||
mitre_attack_id:
|
||||
- T1070.001
|
||||
- T1070
|
||||
nist:
|
||||
- DE.DP
|
||||
- PR.IP
|
||||
|
||||
@@ -32,6 +32,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1059.005
|
||||
- T1059
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -34,6 +34,7 @@ tags:
|
||||
- Exploitation
|
||||
mitre_attack_id:
|
||||
- T1218.012
|
||||
- T1218
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -41,6 +41,7 @@ tags:
|
||||
- T1055
|
||||
- T1543
|
||||
- T1134.004
|
||||
- T1134
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
Reference in New Issue
Block a user